PT-2020-1237 · Libyang · Libyang
Jvijtiuko
·
Published
2020-01-22
·
Updated
2023-09-20
·
CVE-2019-20392
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
libyang versions prior to 1.0-r1
Description
An invalid memory access flaw is present in the function
resolve feature value() when an if-feature statement is used inside a list key node, and the feature used is not defined. Applications that use libyang to parse untrusted input yang files may crash.Recommendations
For versions prior to 1.0-r1, update to version 1.0-r1 or later to resolve the issue. As a temporary workaround, consider avoiding the use of if-feature statements inside list key nodes until a patch is available. Restrict access to untrusted input yang files to minimize the risk of exploitation.
Exploit
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Libyang