Use-after-free in libcomps - CVE-2019-3817

 

Use-after-free in libcomps - CVE-2019-3817

Published: November 18, 2019


Vulnerability identifier: #VU22821
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-3817
CWE-ID: CWE-416
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error when merging two ObjMRTrees while processing XML files in libcomps. A remote attacker can create a specially crafted XML file, pass it to the application, trigger a use-after-free error and crash the application or execute arbitrary code on the system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


Affected software

libcomps
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power
Red Hat Enterprise Linux for x86_64
SUSE Linux
Opensuse

How to mitigate CVE-2019-3817

Install updates from vendor's website.

libcomps - update to 0.1.10

External References

Related Security Bulletins