CVE-2019-20387: High severity centos libsolv vulnerability
Published Jan 21, 2020
·Updated
repodataschema2id in repodata.c in libsolv before 0.7.6 has a heap-based buffer over-read via a last schema whose length is less than the length of the input schema.
Affected Software
2 affected components
openSUSE libsolv<0.7.6
Debian Debian Linux=8.0
Remediation
Patch Available
Event History
Jan 21, 2020
CVE Published
via MITRE·10:54 PM
Data Sourced
via MITRE·10:54 PM
Description
Frequently Asked Questions
1
What is CVE-2019-20387?
CVE-2019-20387 is a vulnerability in libsolv before version 0.7.6 that allows a heap-based buffer over-read.
2
How does CVE-2019-20387 affect Opensuse Libsolv?
CVE-2019-20387 affects Opensuse Libsolv versions before 0.7.6.
3
How does CVE-2019-20387 affect Debian Debian Linux?
CVE-2019-20387 affects Debian Debian Linux version 8.0.
4
What is the severity of CVE-2019-20387?
CVE-2019-20387 has a severity rating of 7.5 (high).
5
How can I fix CVE-2019-20387?
To fix CVE-2019-20387, upgrade to libsolv version 0.7.6 or later.