There is an illegal address access at ext/testcase.c in libsolv.a in libsolv through 0.7.2 that will cause a denial of service. NOTE: third parties dispute this issue stating that the issue affects the test suite and not the underlying library. It cannot be exploited in any real-world application
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.
Link | Tags |
---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=1652604 | issue tracking exploit third party advisory |
https://github.com/openSUSE/libsolv/pull/291 | third party advisory patch |
https://usn.ubuntu.com/3916-1/ | third party advisory vendor advisory |
https://bugzilla.suse.com/show_bug.cgi?id=1120631 | issue tracking third party advisory |
https://access.redhat.com/errata/RHSA-2019:2290 | vendor advisory |
http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00057.html | vendor advisory |
https://access.redhat.com/errata/RHSA-2019:3583 | vendor advisory |