It was discovered that libsolv incorrectly handled certain malformed
input. If a user or automated system were tricked into opening a specially
crafted file, applications that rely on libsolv could be made to crash,
resulting in a denial of service (CVE-2018-2053[2-4]).
- https://bugs.mageia.org/show_bug.cgi?id=24563
- https://ubuntu.com/security/notices/USN-3916-1
- https://www.cve.org/CVERecord?id=CVE-2018-2052
- https://www.cve.org/CVERecord?id=CVE-2018-2053
- https://www.cve.org/CVERecord?id=CVE-2018-2054
- 6/core/libsolv-0.6.30-1.1.mga6
Get the latest Linux and open source security news straight to your inbox.