First published: Wed May 01 2019(Updated: )
An issue was discovered in GNU recutils 1.8. There is a NULL pointer dereference in the function rec_field_name_equal_p at rec-field-name.c in librec.a, leading to a crash.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GNU Recutils | =1.8 | |
debian/recutils | <=1.8-1<=1.9-2<=1.9-3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-11638 has been classified as a moderate severity vulnerability due to its ability to cause a crash through NULL pointer dereference.
To fix CVE-2019-11638, upgrade GNU Recutils to version 1.9 or later, as the vulnerability is resolved in these versions.
CVE-2019-11638 affects GNU Recutils version 1.8 as well as certain Debian packages of Recutils up to version 1.9-3.
CVE-2019-11638 is categorized as a NULL pointer dereference vulnerability, leading to application crashes.
The potential impact of CVE-2019-11638 includes application instability and crashes, which may disrupt services relying on GNU Recutils.