Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5xx9-wg6x-hj24

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

An invalid memory access flaw is present in libyang before v1.0-r1 in the function resolve_feature_value() when an if-feature statement is used inside a list key node, and the feature used is not defined. Applications that use libyang to parse untrusted input yang files may crash.

An invalid memory access flaw is present in libyang before v1.0-r1 in the function resolve_feature_value() when an if-feature statement is used inside a list key node, and the feature used is not defined. Applications that use libyang to parse untrusted input yang files may crash.

EPSS

Процентиль: 42%
0.00203
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-119

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 6 лет назад

An invalid memory access flaw is present in libyang before v1.0-r1 in the function resolve_feature_value() when an if-feature statement is used inside a list key node, and the feature used is not defined. Applications that use libyang to parse untrusted input yang files may crash.

CVSS3: 5.5
redhat
почти 7 лет назад

An invalid memory access flaw is present in libyang before v1.0-r1 in the function resolve_feature_value() when an if-feature statement is used inside a list key node, and the feature used is not defined. Applications that use libyang to parse untrusted input yang files may crash.

CVSS3: 6.5
nvd
около 6 лет назад

An invalid memory access flaw is present in libyang before v1.0-r1 in the function resolve_feature_value() when an if-feature statement is used inside a list key node, and the feature used is not defined. Applications that use libyang to parse untrusted input yang files may crash.

CVSS3: 6.5
debian
около 6 лет назад

An invalid memory access flaw is present in libyang before v1.0-r1 in ...

EPSS

Процентиль: 42%
0.00203
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-119