First published: Sun Dec 13 2020(Updated: )
A flaw was found in libsolv. A buffer overflow vulnerability in the pool_disabled_solvable function allows attackers to cause a denial of service. The highest threat from this vulnerability is to system availability.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/libsolv | <0:0.7.16-3.el8_4 | 0:0.7.16-3.el8_4 |
redhat/libsolv | <0:0.7.22-1.el7 | 0:0.7.22-1.el7 |
redhat/libsolv | <0:0.7.22-1.el8 | 0:0.7.22-1.el8 |
Opensuse Libsolv | <=0.7.17 | |
IBM QRadar SIEM | <=7.5.0 GA | |
IBM QRadar SIEM | <=7.4.3 GA - 7.4.3 FP4 | |
IBM QRadar SIEM | <=7.3.3 GA - 7.3.3 FP10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-33929.
The title of the vulnerability is "Buffer overflow vulnerability in function pool_disabled_solvable in src/repo.h in libsolv before 0.7...".
The severity of CVE-2021-33929 is high.
The highest threat from CVE-2021-33929 is to system availability.
The affected software is libsolv version 0.7.16-3.el8_4, libsolv version 0.7.22-1.el7, libsolv version 0.7.22-1.el8, and IBM QRadar SIEM versions 7.5.0 GA, 7.4.3 GA - 7.4.3 FP4, and 7.3.3 GA - 7.3.3 FP10.
To fix CVE-2021-33929, apply the appropriate patches or updates provided by the software vendors. For IBM QRadar SIEM, you can download the patches from the IBM support website.