CVE-2019-20396: Buffer Overflow
Published Jan 22, 2020
·Updated
A segmentation fault is present in yyparse in libyang before v1.0-r1 due to a malformed pattern statement value during lysparsepath parsing.
Affected Software
11 affected components
CESNET libyang=0.11-r1
CESNET libyang=0.11-r2
CESNET libyang=0.12-r1
CESNET libyang=0.12-r2
CESNET libyang=0.13-r1
CESNET libyang=0.13-r2
CESNET libyang=0.14-r1
CESNET libyang=0.15-r1
CESNET libyang=0.16-r1
CESNET libyang=0.16-r2
CESNET libyang=0.16-r3
Remediation
Event History
Jan 22, 2020
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-20396?
CVE-2019-20396 has been classified with a high severity due to the potential for denial of service resulting from a segmentation fault.
2
How do I fix CVE-2019-20396?
To fix CVE-2019-20396, update libyang to version 1.0-r1 or later where the vulnerability is addressed.
3
What software is affected by CVE-2019-20396?
CVE-2019-20396 affects multiple versions of libyang including 0.11-r1 through 0.16-r3.
4
What type of vulnerability is CVE-2019-20396?
CVE-2019-20396 is a denial of service vulnerability caused by a segmentation fault in the parsing function.
5
Can CVE-2019-20396 be exploited remotely?
Yes, CVE-2019-20396 can be exploited remotely by sending a malformed pattern statement value that triggers the segmentation fault.