Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Mageia: 2020-0117 Moderate: libsolv Out-Of-Bounds Read Issue

mageia
Calendar Grey March 6, 2020
Dist Mageia Esm H88
Recent libsolv updates tackle a vital security vulnerability for Mageia 7 while delivering essential patches.
Updated libsolv packages fix security vulnerability: An out-of-bounds read was discovered in libsolv when the last schema has a length that is less than the length of the input sc...

Summary

Updated libsolv packages fix security vulnerability:
An out-of-bounds read was discovered in libsolv when the last schema has a length that is less than the length of the input schema. A remote attacker may abuse this flaw to crash an application that uses libsolv (CVE-2019-20387).

References

- https://bugs.mageia.org/show_bug.cgi?id=26163

- https://bugzilla.redhat.com/show_bug.cgi?id=1797072

- https://github.com/openSUSE/libsolv/commit/fdb9c9c03508990e4583046b590c30d958f272da

- https://www.cve.org/CVERecord?id=CVE-2019-20387

Resolution

SRPMS

- 7/core/libsolv-0.7.4-1.1.mga7

Severity
important
Lowest
Low
Medium
High
Critical

Publication date: 06 Mar 2020
URL: https://advisories.mageia.org/MGASA-2020-0117.html
Type: security
CVE: CVE-2019-20387

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here