Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-20387

Опубликовано: 21 янв. 2020
Источник: debian

Описание

repodata_schema2id in repodata.c in libsolv before 0.7.6 has a heap-based buffer over-read via a last schema whose length is less than the length of the input schema.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libsolvfixed0.6.36-2package
libsolvfixed0.6.35-2+deb10u1busterpackage
libsolvfixed0.6.24-1+deb9u2stretchpackage

Примечания

  • https://github.com/openSUSE/libsolv/commit/fdb9c9c03508990e4583046b590c30d958f272da (0.7.6)

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 6 лет назад

repodata_schema2id in repodata.c in libsolv before 0.7.6 has a heap-based buffer over-read via a last schema whose length is less than the length of the input schema.

CVSS3: 7.5
redhat
около 6 лет назад

repodata_schema2id in repodata.c in libsolv before 0.7.6 has a heap-based buffer over-read via a last schema whose length is less than the length of the input schema.

CVSS3: 7.5
nvd
около 6 лет назад

repodata_schema2id in repodata.c in libsolv before 0.7.6 has a heap-based buffer over-read via a last schema whose length is less than the length of the input schema.

CVSS3: 7.5
github
больше 3 лет назад

repodata_schema2id in repodata.c in libsolv before 0.7.6 has a heap-based buffer over-read via a last schema whose length is less than the length of the input schema.

oracle-oval
около 5 лет назад

ELSA-2020-4508: libsolv security, bug fix, and enhancement update (MODERATE)