There is an illegal address access at ext/testcase.c in libsolv.a in libsolv through 0.7.2 that will cause a denial of service. NOTE: third parties dispute this issue stating that the issue affects the test suite and not the underlying library. It cannot be exploited in any real-world application

Subscriptions

Vendors Products
Canonical Subscribe
Ubuntu Linux Subscribe
Opensuse Subscribe
Libsolv Subscribe
Enterprise Linux Subscribe

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Ubuntu USN Ubuntu USN USN-3916-1 libsolv vulnerabilities
Ubuntu USN Ubuntu USN USN-4851-1 Libsolv vulnerabilities
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-05T12:05:17.450Z

Reserved: 2018-12-27T00:00:00.000Z

Link: CVE-2018-20534

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-12-28T16:29:04.330

Modified: 2024-11-21T04:01:40.267

Link: CVE-2018-20534

cve-icon Redhat

Severity : Low

Publid Date: 2018-11-22T00:00:00Z

Links: CVE-2018-20534 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses