Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-20395

Опубликовано: 08 мар. 2019
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

A stack consumption issue is present in libyang before v1.0-r1 due to the self-referential union type containing leafrefs. Applications that use libyang to parse untrusted input yang files may crash.

A stack-overflow flaw was found in libyang due to a self-referential union type containing leafrefs. Applications that use libyang to process untrusted input YANG files may crash while processing malformed files.

Дополнительная информация

Статус:

Low
Дефект:
CWE-674
https://bugzilla.redhat.com/show_bug.cgi?id=1793924libyang: stack-overflow when parsing yang files with self-referential union types

EPSS

Процентиль: 77%
0.01839
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 6 лет назад

A stack consumption issue is present in libyang before v1.0-r1 due to the self-referential union type containing leafrefs. Applications that use libyang to parse untrusted input yang files may crash.

CVSS3: 6.5
nvd
больше 6 лет назад

A stack consumption issue is present in libyang before v1.0-r1 due to the self-referential union type containing leafrefs. Applications that use libyang to parse untrusted input yang files may crash.

CVSS3: 6.5
debian
больше 6 лет назад

A stack consumption issue is present in libyang before v1.0-r1 due to ...

CVSS3: 6.5
github
около 4 лет назад

A stack consumption issue is present in libyang before v1.0-r1 due to the self-referential union type containing leafrefs. Applications that use libyang to parse untrusted input yang files may crash.

EPSS

Процентиль: 77%
0.01839
Низкий

5.5 Medium

CVSS3

Уязвимость CVE-2019-20395