REDHAT-BUG-2477617: Buffer Overflow
libyang is a YANG data modeling language library. Prior to SO 5.2.15, lybreadstring() in src/parserlyb.c contains an integer overflow that results in a heap buffer overflow when parsing a maliciously crafted LYB binary blob. An attacker who can supply LYB data to any libyang consumer (NETCONF server, sysrepo, etc.) can trigger a crash or potential heap corruption. This vulnerability is fixed in SO 5.2.15.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
libyangto a version that resolves this vulnerability.Fixed in 5.2.15
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2477617?
The severity of REDHAT-BUG-2477617 is rated high with a score of 7.
How do I fix REDHAT-BUG-2477617?
To fix REDHAT-BUG-2477617, upgrade to version SO 5.2.15 or later of the libyang library.
What kind of vulnerability is REDHAT-BUG-2477617?
REDHAT-BUG-2477617 is an integer overflow vulnerability that can lead to a heap buffer overflow.
What components are affected by REDHAT-BUG-2477617?
The CESNET libyang library is affected by REDHAT-BUG-2477617.
What potential impact does REDHAT-BUG-2477617 have?
Exploitation of REDHAT-BUG-2477617 can allow attackers to execute arbitrary code via malicious LYB data.