CVE-2020-23914

Source
https://cve.org/CVERecord?id=CVE-2020-23914
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-23914.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2020-23914
Downstream
Published
2021-04-21T18:15:08.237Z
Modified
2026-02-24T08:14:34.833171Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

An issue was discovered in cpp-peglib through v0.1.12. A NULL pointer dereference exists in the peg::AstOptimizer::optimize() located in peglib.h. It allows an attacker to cause Denial of Service.

References

Affected packages

Git / github.com/yhirose/cpp-peglib

Affected ranges

Type
GIT
Repo
https://github.com/yhirose/cpp-peglib
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

v0.*
v0.1.0
v0.1.1
v0.1.10
v0.1.11
v0.1.12
v0.1.2
v0.1.3
v0.1.4
v0.1.5
v0.1.6
v0.1.7
v0.1.8
v0.1.9

Database specific

vanir_signatures
[
    {
        "id": "CVE-2020-23914-69176862",
        "signature_version": "v1",
        "deprecated": false,
        "source": "https://github.com/yhirose/cpp-peglib/commit/0061f393de54cf0326621c079dc2988336d1ebb3",
        "target": {
            "file": "peglib.h"
        },
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "143327657411845853706364732432047714027",
                "334920685749213769228073951731449746527",
                "12291384508830736500925591445046188984",
                "183003434346659421475079663696476586312",
                "138597885167665837198154317017487449694",
                "162740308102681216509902116999422262881",
                "141486962610510453940099920915013980409",
                "227739702468128197815300046015901413046",
                "39693275491623016054556102765444652823",
                "210855172614649982907027233225598125993",
                "253555357260913864384411709209377704997"
            ]
        },
        "signature_type": "Line"
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-23914.json"