CVE-2018-20532

Description

There is a NULL pointer dereference at ext/testcase.c (function testcase_read) in libsolvext.a in libsolv through 0.7.2 that will cause a denial of service.

Risk Information

Base Score
6.5
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
0.499

Associated Vulnerability

VulnerabilityOS Platform
A dependency solver using a satisfiablility algorithm (USN-3916-1) libsolv0_0.6.35-2ubuntu0.18.10.1_i386.debLinux
A dependency solver using a satisfiablility algorithm (USN-3916-1) libsolv0_0.6.35-2ubuntu0.18.10.1_amd64.debLinux
A dependency solver using a satisfiablility algorithm (USN-3916-1) libsolvext0_0.6.35-2ubuntu0.18.10.1_i386.debLinux
A dependency solver using a satisfiablility algorithm (USN-3916-1) libsolvext0_0.6.35-2ubuntu0.18.10.1_amd64.debLinux
A dependency solver using a satisfiablility algorithm (USN-3916-1) libsolv-tools_0.6.35-2ubuntu0.18.10.1_i386.debLinux
A dependency solver using a satisfiablility algorithm (USN-3916-1) libsolv-tools_0.6.35-2ubuntu0.18.10.1_amd64.debLinux
SUSE-SU-2019:1972-1(SUSE Linux Enterprise Server 12-SP5) libsolv-debugsource-0.6.36-2.16.2.x86_64.rpmLinux
SUSE-SU-2019:1972-1(SUSE Linux Enterprise Server 12-SP5) libsolv-tools-0.6.36-2.16.2.x86_64.rpmLinux
SUSE-SU-2019:1972-1(SUSE Linux Enterprise Server 12-SP5) libsolv-tools-debuginfo-0.6.36-2.16.2.x86_64.rpmLinux
SUSE-SU-2019:1972-1(SUSE Linux Enterprise Server 12-SP5) libzypp-16.20.0-2.39.4.x86_64.rpmLinux
SUSE-SU-2019:1972-1(SUSE Linux Enterprise Server 12-SP5) libzypp-debuginfo-16.20.0-2.39.4.x86_64.rpmLinux
SUSE-SU-2019:1972-1(SUSE Linux Enterprise Server 12-SP5) libzypp-debugsource-16.20.0-2.39.4.x86_64.rpmLinux
SUSE-SU-2019:1972-1(SUSE Linux Enterprise Server 12-SP5) perl-solv-0.6.36-2.16.2.x86_64.rpmLinux
SUSE-SU-2019:1972-1(SUSE Linux Enterprise Server 12-SP5) perl-solv-debuginfo-0.6.36-2.16.2.x86_64.rpmLinux
SUSE-SU-2019:1972-1(SUSE Linux Enterprise Server 12-SP5) python-solv-0.6.36-2.16.2.x86_64.rpmLinux
SUSE-SU-2019:1972-1(SUSE Linux Enterprise Server 12-SP5) python-solv-debuginfo-0.6.36-2.16.2.x86_64.rpmLinux
SUSE-SU-2019:1972-1(SUSE Linux Enterprise Server 12-SP5) zypper-1.13.51-21.26.4.x86_64.rpmLinux
SUSE-SU-2019:1972-1(SUSE Linux Enterprise Server 12-SP5) zypper-debuginfo-1.13.51-21.26.4.x86_64.rpmLinux
SUSE-SU-2019:1972-1(SUSE Linux Enterprise Server 12-SP5) zypper-debugsource-1.13.51-21.26.4.x86_64.rpmLinux
SUSE-SU-2019:1972-1(SUSE Linux Enterprise Server 12-SP5) zypper-log-1.13.51-21.26.4.noarch.rpmLinux
(RHSA-2019:2290)Low: security and bug fix update libsolv-debuginfo-0.6.34-4.el7.i686.rpmLinux
(RHSA-2019:2290)Low: security and bug fix update libsolv-debuginfo-0.6.34-4.el7.x86_64.rpmLinux
libsolv Security Update (ALAS-2019-1374) libsolv-0.6.34-4.amzn2.i686.rpmLinux
libsolv Security Update (ALAS-2019-1374) libsolv-0.6.34-4.amzn2.x86_64.rpmLinux
libsolv Security Update (ALAS-2019-1374) libsolv-demo-0.6.34-4.amzn2.x86_64.rpmLinux
libsolv Security Update (ALAS-2019-1374) python2-solv-0.6.34-4.amzn2.x86_64.rpmLinux
libsolv Security Update (ALAS-2019-1374) libsolv-devel-0.6.34-4.amzn2.x86_64.rpmLinux
libsolv Security Update (ALAS-2019-1374) libsolv-tools-0.6.34-4.amzn2.x86_64.rpmLinux
NULL Pointer Dereference Vulnerability (CVE-2018-20532)NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234