CVE-2018-20532: Null Pointer Dereference
A vulnerability was found in libsolv through 0.7.2. There is a NULL pointer dereference at ext/testcase.c (function testcaseread) in libsolvext.a that will cause a denial of service.
References: https://bugzilla.redhat.com/showbug.cgi?id=1652605
Upstream Patch: https://github.com/openSUSE/libsolv/pull/291
Other sources
There is a NULL pointer dereference at ext/testcase.c (function testcaseread) in libsolvext.a in libsolv through 0.7.2 that will cause a denial of service.
— Launchpad
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2018-20532?
CVE-2018-20532 is a vulnerability that allows a NULL pointer dereference in libsolv through 0.7.2, leading to a denial of service.
Which software is affected by CVE-2018-20532?
The affected software includes libsolv 0.6.35-2+deb10u1, libsolv 0.6.35-2ubuntu0.18.10.1, libsolv 0.6.5-2ubuntu1, and more.
What is the severity of CVE-2018-20532?
CVE-2018-20532 has a severity rating of 6.5 (medium).
How can I fix CVE-2018-20532?
To fix CVE-2018-20532, update to libsolv version 0.7.17-1, 0.7.23-1, or 0.7.25-1.
Where can I find more information about CVE-2018-20532?
You can find more information about CVE-2018-20532 at the following references: http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00057.html, https://access.redhat.com/errata/RHSA-2019:2290, and https://bugzilla.redhat.com/show_bug.cgi?id=1652605.