Описание
Buffer overflow vulnerability in libsolv 2020-12-13 via the Solver * testcase_read(Pool *pool, FILE *fp, const char *testcase, Queue *job, char **resultp, int *resultflagsp function at src/testcase.c: line 2334, which could cause a denial of service
A flaw was found in libsolv. A buffer overflow vulnerability could cause a denial of service. The highest threat from this vulnerability is to system availability.
Отчет
It is not clear how this flaw could cause denial of service in most practical situations in general, and it is not the case in Red Hat Enterprise Linux package management, therefore we have lowered the Impact to Low. This is due to the fact that it is a small out of bounds read triggered by the testsolv program in the code used to evaluate testcases: https://github.com/openSUSE/libsolv/blob/master/doc/testsolv.txt Red Hat Update Infrastructure 3.1 is in the maintenance phase and we will not be fixing Medium/Low impact security bugs. Reference: https://access.redhat.com/support/policy/updates/rhui
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Ansible Automation Platform 1.2 | libsolv | Affected | ||
| Red Hat Enterprise Linux 7 | libsolv | Out of support scope | ||
| Red Hat Enterprise Linux 9 | libsolv | Not affected | ||
| Red Hat Update Infrastructure 3 for Cloud Providers | libsolv | Will not fix | ||
| Red Hat Enterprise Linux 8 | libsolv | Fixed | RHSA-2021:4408 | 09.11.2021 |
| Red Hat Satellite 6.11 for RHEL 7 | libsolv | Fixed | RHSA-2022:5498 | 05.07.2022 |
| Red Hat Satellite 6.11 for RHEL 7 | libsolv | Fixed | RHSA-2022:5498 | 05.07.2022 |
| Red Hat Satellite 6.11 for RHEL 8 | libsolv | Fixed | RHSA-2022:5498 | 05.07.2022 |
| Red Hat Satellite 6.11 for RHEL 8 | libsolv | Fixed | RHSA-2022:5498 | 05.07.2022 |
Показывать по
Дополнительная информация
Статус:
EPSS
3.3 Low
CVSS3
Связанные уязвимости
Buffer overflow vulnerability in libsolv 2020-12-13 via the Solver * testcase_read(Pool *pool, FILE *fp, const char *testcase, Queue *job, char **resultp, int *resultflagsp function at src/testcase.c: line 2334, which could cause a denial of service
Buffer overflow vulnerability in libsolv 2020-12-13 via the Solver * testcase_read(Pool *pool, FILE *fp, const char *testcase, Queue *job, char **resultp, int *resultflagsp function at src/testcase.c: line 2334, which could cause a denial of service
Buffer overflow vulnerability in libsolv 2020-12-13 via the Solver * testcase_read(Pool *pool FILE *fp const char *testcase Queue *job char **resultp int *resultflagsp function at src/testcase.c: line 2334 which could cause a denial of service
Buffer overflow vulnerability in libsolv 2020-12-13 via the Solver * t ...
EPSS
3.3 Low
CVSS3