logo

Vulnerability Discovery in Open Source Libraries: Analyzing CVE-2020-11863

ID: a6ea83b0-6b02-500d-976b-a0c69317800a

STIX ID: report--a6ea83b0-6b02-500d-976b-a0c69317800a

Feed Name: McAfee Labs Blog

Threat Score
40/100

Date Published: 2020-09-01

Date Updated: 2026-04-28

Author: Chintan Shah

...
...

This McAfee Labs blog provides a deep-dive analysis of libEMF vulnerabilities (notably CVE-2020-11863 and CVE-2020-11865), showing how an out-of-bounds access to a global stock-object vector during EMR_SELECTOBJECT processing combined with uninitialized memory (ASAN fill 0xBE) leads to dereferencing a bogus vtable and a crash; the post explains reproduction steps, ASAN behavior, and notes that fixes have been released, while recommending fuzzing and stronger collaboration with open-source maintainers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.