{"id":"CVE-2020-18897","details":"An use-after-free vulnerability in the libpff_item_tree_create_node function of libyal Libpff before 20180623 allows attackers to cause a denial of service (DOS) or execute arbitrary code via a crafted pff file.","modified":"2026-03-14T10:14:31.126242Z","published":"2021-08-19T22:15:07.167Z","references":[{"type":"REPORT","url":"https://github.com/libyal/libpff/issues/62"},{"type":"FIX","url":"https://github.com/libyal/libpff/issues/61"}],"affected":[{"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-18897.json","unresolved_ranges":[{"events":[{"introduced":"0"},{"fixed":"20180623"}]},{"events":[{"introduced":"0"},{"fixed":"20180623"}]}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}