CVE-2019-6460: Null Pointer Dereference
Published Jan 16, 2019
·Updated
An issue was discovered in GNU Recutils 1.8. There is a NULL pointer dereference in the function recfieldsetname() in the file rec-field.c in librec.a.
Affected Software
2 affected components
GNU recutils=1.8
debian/recutils<=1.8-1, <=1.9-2, <=1.9-3
Event History
Jan 16, 2019
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Dec 4, 2024
Data Sourced
via Launchpad·08:56 PM
Description
Dec 8, 2024
Data Sourced
via Ubuntu·08:56 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2019-6460?
CVE-2019-6460 is classified as a medium-severity vulnerability due to the risk of application crashes caused by NULL pointer dereference.
2
How do I fix CVE-2019-6460?
To fix CVE-2019-6460, upgrade GNU Recutils to version 1.9 or later to mitigate the NULL pointer dereference issue.
3
What software is affected by CVE-2019-6460?
CVE-2019-6460 affects GNU Recutils version 1.8 and certain versions of the package recutils in Debian.
4
What type of vulnerability is CVE-2019-6460?
CVE-2019-6460 is a NULL pointer dereference vulnerability found in the rec_field_set_name function.
5
Is CVE-2019-6460 exploitable?
Yes, CVE-2019-6460 can be exploited to crash the application that uses the vulnerable version of GNU Recutils.