First published: Fri Dec 28 2018(Updated: )
** DISPUTED ** There is an illegal address access at ext/testcase.c in libsolv.a in libsolv through 0.7.2 that will cause a denial of service. NOTE: third parties dispute this issue stating that the issue affects the test suite and not the underlying library. It cannot be exploited in any real-world application.
Credit: cve@mitre.org cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Opensuse Libsolv | <=0.7.2 | |
Canonical Ubuntu Linux | =18.10 | |
debian/libsolv | 0.7.17-1+deb11u1 0.7.23-1+deb12u1 0.7.30-1 0.7.30-2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-20534
The severity of CVE-2018-20534 is medium (6.5).
The software affected by CVE-2018-20534 is libsolv.
CVE-2018-20534 cannot be exploited in any real-world scenario.
To fix CVE-2018-20534, update to version 0.7.17-1, 0.7.23-1, or 0.7.25-1 of libsolv.