Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5xx9-wg6x-hj24

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

An invalid memory access flaw is present in libyang before v1.0-r1 in the function resolve_feature_value() when an if-feature statement is used inside a list key node, and the feature used is not defined. Applications that use libyang to parse untrusted input yang files may crash.

An invalid memory access flaw is present in libyang before v1.0-r1 in the function resolve_feature_value() when an if-feature statement is used inside a list key node, and the feature used is not defined. Applications that use libyang to parse untrusted input yang files may crash.

EPSS

Процентиль: 77%
0.01859
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-119

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 6 лет назад

An invalid memory access flaw is present in libyang before v1.0-r1 in the function resolve_feature_value() when an if-feature statement is used inside a list key node, and the feature used is not defined. Applications that use libyang to parse untrusted input yang files may crash.

CVSS3: 5.5
redhat
больше 7 лет назад

An invalid memory access flaw is present in libyang before v1.0-r1 in the function resolve_feature_value() when an if-feature statement is used inside a list key node, and the feature used is not defined. Applications that use libyang to parse untrusted input yang files may crash.

CVSS3: 6.5
nvd
больше 6 лет назад

An invalid memory access flaw is present in libyang before v1.0-r1 in the function resolve_feature_value() when an if-feature statement is used inside a list key node, and the feature used is not defined. Applications that use libyang to parse untrusted input yang files may crash.

CVSS3: 6.5
debian
больше 6 лет назад

An invalid memory access flaw is present in libyang before v1.0-r1 in ...

EPSS

Процентиль: 77%
0.01859
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-119