Severity
3.3LOWNVD
EPSS
0.0%
top 90.60%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 18
Latest updateMay 24

Description

Buffer overflow vulnerability in libsolv 2020-12-13 via the Solver * testcase_read(Pool *pool, FILE *fp, const char *testcase, Queue *job, char **resultp, int *resultflagsp function at src/testcase.c: line 2334, which could cause a denial of service

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:LExploitability: 1.8 | Impact: 1.4

Affected Packages3 packages

Patches

🔴Vulnerability Details

3
GHSA
GHSA-cphx-qv3m-4vvc: Buffer overflow vulnerability in libsolv 2020-12-13 via the Solver * testcase_read(Pool *pool, FILE *fp, const char *testcase, Queue *job, char **resu2022-05-24
OSV
CVE-2021-3200: Buffer overflow vulnerability in libsolv 2020-12-13 via the Solver * testcase_read(Pool *pool, FILE *fp, const char *testcase, Queue *job, char **resu2021-05-18
CVEList
CVE-2021-3200: Buffer overflow vulnerability in libsolv 2020-12-13 via the Solver * testcase_read(Pool *pool, FILE *fp, const char *testcase, Queue *job, char **resu2021-05-18

📋Vendor Advisories

12
Oracle
Oracle Oracle Communications Risk Matrix: Signaling (libsolv) — CVE-2021-32002022-04-15
Red Hat
libsolv: Heap overflow2022-02-21
Red Hat
libsolv: Heap overflow2022-02-21
Red Hat
libsolv: Heap overflow2022-02-21
Red Hat
libsolv: Heap overflow2022-02-21
CVE-2021-3200 — Classic Buffer Overflow in Libsolv | cvebase