Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-20387

Опубликовано: 21 янв. 2020
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

repodata_schema2id in repodata.c in libsolv before 0.7.6 has a heap-based buffer over-read via a last schema whose length is less than the length of the input schema.

An out-of-bounds read was discovered in Libsolv when the last schema has a length that is less than the length of the input schema. A remote attacker may abuse this flaw to crash an application that uses Libsolv.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7libsolvWill not fix
Red Hat Satellite 6libsolvNot affected
Red Hat Update Infrastructure 3 for Cloud ProviderslibsolvWill not fix
Red Hat Enterprise Linux 8libsolvFixedRHSA-2020:450804.11.2020

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=1797072libsolv: out-of-bounds read in repodata_schema2id in repodata.c

EPSS

Процентиль: 46%
0.0023
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 6 лет назад

repodata_schema2id in repodata.c in libsolv before 0.7.6 has a heap-based buffer over-read via a last schema whose length is less than the length of the input schema.

CVSS3: 7.5
nvd
около 6 лет назад

repodata_schema2id in repodata.c in libsolv before 0.7.6 has a heap-based buffer over-read via a last schema whose length is less than the length of the input schema.

CVSS3: 7.5
debian
около 6 лет назад

repodata_schema2id in repodata.c in libsolv before 0.7.6 has a heap-ba ...

CVSS3: 7.5
github
больше 3 лет назад

repodata_schema2id in repodata.c in libsolv before 0.7.6 has a heap-based buffer over-read via a last schema whose length is less than the length of the input schema.

oracle-oval
около 5 лет назад

ELSA-2020-4508: libsolv security, bug fix, and enhancement update (MODERATE)

EPSS

Процентиль: 46%
0.0023
Низкий

7.5 High

CVSS3