First published: Wed Jan 16 2019(Updated: )
An issue was discovered in GNU Recutils 1.8. There is a NULL pointer dereference in the function rec_fex_size() in the file rec-fex.c of librec.a.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GNU Recutils | =1.8 | |
debian/recutils | <=1.8-1<=1.9-2<=1.9-3 | |
=1.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-6456 has a medium severity due to the potential for a denial of service caused by a NULL pointer dereference.
To fix CVE-2019-6456, upgrade GNU Recutils to version 1.9 or later, where the vulnerability has been addressed.
GNU Recutils version 1.8 is affected by CVE-2019-6456, while later versions are not.
CVE-2019-6456 represents a NULL pointer dereference vulnerability that can lead to a denial of service.
Detailed information about CVE-2019-6456 can be typically found in the security advisories or vulnerability databases.