PT-2020-10413 · Opensuse+3 · Libsolv+3

Published

2020-01-21

·

Updated

2023-01-31

·

CVE-2019-20387

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions libsolv versions prior to 0.7.6
Description The issue is related to a heap-based buffer over-read in the repodata schema2id function in repodata.c. This occurs when the length of the last schema is less than the length of the input schema.
Recommendations For versions prior to 0.7.6, update to version 0.7.6 or later to resolve the issue.

Exploit

Fix

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CESA-2020_4508
CVE-2019-20387
DLA-2088-1
MGASA-2020-0117
RHSA-2020:4508
RHSA-2020_4508
SUSE-SU-2021:2145-1
SUSE-SU-2021:2180-1
SUSE-SU-2021_2145-1
SUSE-SU-2021_2180-1

Affected Products

Centos
Red Hat
Suse
Libsolv