First published: Thu Sep 02 2021(Updated: )
Libsolv is vulnerable to a denial of service, caused by a heap-based buffer overflow in the pool_installable_whatprovides in src/repo.h function. A remote attacker could exploit this vulnerability to cause a denial of service.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Opensuse Libsolv | <=0.7.17 | |
IBM QRadar SIEM | <=7.5.0 GA | |
IBM QRadar SIEM | <=7.4.3 GA - 7.4.3 FP4 | |
IBM QRadar SIEM | <=7.3.3 GA - 7.3.3 FP10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-33930 is a vulnerability in Libsolv that can be exploited by a remote attacker to cause a denial of service.
The severity of CVE-2021-33930 is medium, with a severity value of 5.3.
Libsolv version up to exclusive 0.7.17, IBM QRadar SIEM versions 7.5.0 GA, 7.4.3 GA - 7.4.3 FP4, and 7.3.3 GA - 7.3.3 FP10 are affected by CVE-2021-33930.
To fix CVE-2021-33930, update Libsolv to version 0.7.17 or apply the respective patches for the affected IBM QRadar SIEM versions.
More information about CVE-2021-33930 can be found in the references provided: [GitHub Issue](https://github.com/openSUSE/libsolv/issues/417), [Red Hat Bugzilla](https://bugzilla.redhat.com/show_bug.cgi?id=2000706), [GitHub Commit](https://github.com/openSUSE/libsolv/commit/0077ef29eb46d2e1df2f230fc95a1d9748d49dec).