A vulnerability was found in libsolv through 0.7.2. There is a NULL pointer dereference at ext/testcase.c (function testcaseread) in libsolvext.a that will cause a denial of service.
References: https://bugzilla.redhat.com/showbug.cgi?id=1652605
Upstream Patch: https://github.com/openSUSE/libsolv/pull/291
A vulnerability was found in libsolv through 0.7.2. There is a NULL pointer dereference at ext/testcase.c (function testcasestr2depcomplex) in libsolvext.a in libsolv that will cause a denial of service.
References: https://bugzilla.redhat.com/showbug.cgi?id=1652599
Upstream Patch: https://github.com/openSUSE/libsolv/pull/291
DISPUTED There is an illegal address access at ext/testcase.c in libsolv.a in libsolv through 0.7.2 that will cause a denial of service. NOTE: third parties dispute this issue stating that the issue affects the test suite and not the underlying library. It cannot be exploited in any real-world application.