There is an illegal address access at ext/testcase.c in libsolv.a in libsolv through 0.7.2 that will cause a denial of service. NOTE: third parties dispute this issue stating that the issue affects the test suite and not the underlying library. It cannot be exploited in any real-world application
📦
libsolv
Vendor: opensuse
Actively Exploited
0
CISA KEV List
PoC / Exploits
0
Code Available
Total RCEs
1
Remote Access
Total CVEs
27
Total Indexed
Avg. EPSS
1.44%
Exploit Prob.
Security Vulnerability Index
Page 2 / 3
6.5
CVSS
Severity: MEDIUM
6.5
CVSS
There is a NULL pointer dereference at ext/testcase.c (function testcase_str2dep_complex) in libsolvext.a in libsolv through 0.7.2 that will cause a denial of service.
Severity: MEDIUM
6.5
CVSS
There is a NULL pointer dereference at ext/testcase.c (function testcase_read) in libsolvext.a in libsolv through 0.7.2 that will cause a denial of service.
Severity: MEDIUM