CVE-2018-20533: Null Pointer Dereference
A vulnerability was found in libsolv through 0.7.2. There is a NULL pointer dereference at ext/testcase.c (function testcasestr2depcomplex) in libsolvext.a in libsolv that will cause a denial of service.
References: https://bugzilla.redhat.com/showbug.cgi?id=1652599
Upstream Patch: https://github.com/openSUSE/libsolv/pull/291
Other sources
There is a NULL pointer dereference at ext/testcase.c (function testcasestr2depcomplex) in libsolvext.a in libsolv through 0.7.2 that will cause a denial of service.
— Launchpad
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2018-20533?
CVE-2018-20533 is a vulnerability that involves a NULL pointer dereference in libsolvext.a in libsolv through version 0.7.2, which can result in a denial of service.
How severe is CVE-2018-20533?
CVE-2018-20533 has a severity score of 6.5, which is classified as medium severity.
Which software is affected by CVE-2018-20533?
The software affected by CVE-2018-20533 includes libsolv versions 0.6.35-2+deb10u1, 0.7.3, and versions 0.7.17-1, 0.7.23-1, 0.7.25-1 from the Debian repository.
How can I fix CVE-2018-20533 in Debian?
To fix CVE-2018-20533 in Debian, update the libsolv package to version 0.6.35-2+deb10u1 or one of the recommended versions.
Where can I find more information about CVE-2018-20533?
More information about CVE-2018-20533 can be found at the following references: [http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00057.html](http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00057.html), [https://access.redhat.com/errata/RHSA-2019:2290](https://access.redhat.com/errata/RHSA-2019:2290), [https://bugzilla.redhat.com/show_bug.cgi?id=1652599](https://bugzilla.redhat.com/show_bug.cgi?id=1652599).