Stack-based buffer overflow in libyang - CVE-2019-19334

 

Stack-based buffer overflow in libyang - CVE-2019-19334

Published: December 23, 2019


Vulnerability identifier: #VU23798
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-19334
CWE-ID: CWE-121
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error when libyang parses YANG files with a leaf of type "identityref". A remote unauthenticated attacker can pass to the application an untrusted YANG file, trigger stack-based buffer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

libyang
Dell EMC PowerProtect Data Protection
SmartFabric OS10
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux Server
Fedora
libyang

How to mitigate CVE-2019-19334

Install update from vendor's website.

libyang - update to 1.0-r5
Dell EMC PowerProtect Data Protection - update to 2.7.8
SmartFabric OS10 - addressed in versions 10.5.5.9, 10.5.6.1
libyang - addressed in versions 1.0.101-1.fc30, 1.0.101-1.fc31

External References

Related Security Bulletins