Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-33938

Опубликовано: 13 дек. 2020
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Buffer overflow vulnerability in function prune_to_recommended in src/policy.c in libsolv before 0.7.17 allows attackers to cause a Denial of Service.

A flaw was found in libsolv. A buffer overflow vulnerability in the prune_to_recommend function allows attackers to cause a denial of service. The highest threat from this vulnerability is to system availability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ansible Automation Platform 1.2libsolvNot affected
Red Hat Enterprise Linux 7libsolvOut of support scope
Red Hat Enterprise Linux 9libsolvNot affected
Red Hat Update Infrastructure 3 for Cloud ProviderslibsolvWill not fix
Red Hat Enterprise Linux 8libsolvFixedRHSA-2021:406002.11.2021
Red Hat Satellite 6.11 for RHEL 7libsolvFixedRHSA-2022:549805.07.2022
Red Hat Satellite 6.11 for RHEL 7libsolvFixedRHSA-2022:549805.07.2022
Red Hat Satellite 6.11 for RHEL 8libsolvFixedRHSA-2022:549805.07.2022
Red Hat Satellite 6.11 for RHEL 8libsolvFixedRHSA-2022:549805.07.2022

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-119
https://bugzilla.redhat.com/show_bug.cgi?id=2000707libsolv: heap-based buffer overflow in prune_to_recommended() in src/policy.c

EPSS

Процентиль: 16%
0.00051
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 4 года назад

Buffer overflow vulnerability in function prune_to_recommended in src/policy.c in libsolv before 0.7.17 allows attackers to cause a Denial of Service.

CVSS3: 7.5
nvd
почти 4 года назад

Buffer overflow vulnerability in function prune_to_recommended in src/policy.c in libsolv before 0.7.17 allows attackers to cause a Denial of Service.

CVSS3: 7.5
msrc
почти 4 года назад

Описание отсутствует

CVSS3: 7.5
debian
почти 4 года назад

Buffer overflow vulnerability in function prune_to_recommended in src/ ...

github
около 3 лет назад

Buffer overflow vulnerability in function prune_to_recommended in src/policy.c in libsolv before 0.7.17 allows attackers to cause a Denial of Service.

EPSS

Процентиль: 16%
0.00051
Низкий

7.5 High

CVSS3