First published: Wed Jan 16 2019(Updated: )
An issue was discovered in GNU Recutils 1.8. There is a NULL pointer dereference in the function rec_field_set_name() in the file rec-field.c in librec.a.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GNU Recutils | =1.8 | |
debian/recutils | <=1.8-1<=1.9-2<=1.9-3 | |
=1.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-6460 is classified as a medium-severity vulnerability due to the risk of application crashes caused by NULL pointer dereference.
To fix CVE-2019-6460, upgrade GNU Recutils to version 1.9 or later to mitigate the NULL pointer dereference issue.
CVE-2019-6460 affects GNU Recutils version 1.8 and certain versions of the package recutils in Debian.
CVE-2019-6460 is a NULL pointer dereference vulnerability found in the rec_field_set_name function.
Yes, CVE-2019-6460 can be exploited to crash the application that uses the vulnerable version of GNU Recutils.