CVE-2018-20534: Buffer Overflow
DISPUTED There is an illegal address access at ext/testcase.c in libsolv.a in libsolv through 0.7.2 that will cause a denial of service. NOTE: third parties dispute this issue stating that the issue affects the test suite and not the underlying library. It cannot be exploited in any real-world application.
Other sources
A vulnerability was found in libsolv through 0.7.2. There is an illegal address access at src/pool.h (function poolwhatprovides) in libsolv.a that will cause a denial of service.
References: https://bugzilla.redhat.com/showbug.cgi?id=1652604
Upstream Patch: https://github.com/openSUSE/libsolv/pull/291
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID?
CVE-2018-20534
What is the severity of CVE-2018-20534?
The severity of CVE-2018-20534 is medium (6.5).
Which software is affected by CVE-2018-20534?
The software affected by CVE-2018-20534 is libsolv.
How can CVE-2018-20534 be exploited?
CVE-2018-20534 cannot be exploited in any real-world scenario.
How can I fix CVE-2018-20534?
To fix CVE-2018-20534, update to version 0.7.17-1, 0.7.23-1, or 0.7.25-1 of libsolv.