Total vulnerabilities in the database
libuci in OpenWrt before 18.06.9 and 19.x before 19.07.5 may encounter a use after free when using malicious package names. This is related to uci_parse_package in file.c and uci_strdup in util.c.
Software | From | Fixed in |
---|---|---|
openwrt / openwrt | 19.07.0 | 19.07.5 |
openwrt / openwrt | - | 18.06.9 |