ZeroHour

CVE-2019-20387

CVSS 3.1
7.5 high
EPSS
2%p83
Published
()
Modified
Description

repodata_schema2id in repodata.c in libsolv before 0.7.6 has a heap-based buffer over-read via a last schema whose length is less than the length of the input schema.

Vendors
opensusedebian
Products
libsolv, debian linux
Weakness
CWE-125
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.