Out-of-bounds read in libsolv - CVE-2019-20387
Published: January 22, 2020
Vulnerability identifier: #VU24490
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-20387
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to heap-based buffer over-read via a last schema whose length is less than the length of the input schema. A remote attacker can perform a denial of service attack.
Affected software
libsolv
libsolv (Red Hat package)
python-solv-debuginfo
libsolv-debugsource
libsolv-devel
libsolv-tools
libsolv-tools-debuginfo
python-solv
perl-solv-debuginfo
perl-solv
libsolv-devel-debuginfo
python3-solv
libsolv
libzypp
libzypp-debuginfo
libzypp-debugsource
libzypp-devel
libzypp-devel-doc
Red Hat OpenShift Serverless
Quay
OpenShift Data Foundation (formerly OpenShift Container Storage)
Red Hat Enterprise Linux for IBM z Systems
Anolis OS
HPE Helion Openstack
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for x86_64
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Software Development Kit
libsolv (Red Hat package)
python-solv-debuginfo
libsolv-debugsource
libsolv-devel
libsolv-tools
libsolv-tools-debuginfo
python-solv
perl-solv-debuginfo
perl-solv
libsolv-devel-debuginfo
python3-solv
libsolv
libzypp
libzypp-debuginfo
libzypp-debugsource
libzypp-devel
libzypp-devel-doc
Red Hat OpenShift Serverless
Quay
OpenShift Data Foundation (formerly OpenShift Container Storage)
Red Hat Enterprise Linux for IBM z Systems
Anolis OS
HPE Helion Openstack
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for x86_64
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Software Development Kit
How to mitigate CVE-2019-20387
Install update from vendor's website.
libsolv - update to 0.7.6
libsolv (Red Hat package) - update to 0.7.11-1.el8
Red Hat OpenShift Serverless - addressed in versions 1.10.2, 1.11.0, 1.12.0
Quay - update to 3.3.3
python-solv-debuginfo - addressed in versions 0.6.37-2.27.24.1, 0.6.37-2.33.1
libsolv-debugsource - addressed in versions 0.6.37-2.27.24.1, 0.6.37-2.33.1
libsolv-devel - addressed in versions 0.6.37-2.27.24.1, 0.6.37-2.33.1
libsolv-tools - addressed in versions 0.6.37-2.27.24.1, 0.6.37-2.33.1
libsolv-tools-debuginfo - addressed in versions 0.6.37-2.27.24.1, 0.6.37-2.33.1
python-solv - addressed in versions 0.6.37-2.27.24.1, 0.6.37-2.33.1
perl-solv-debuginfo - addressed in versions 0.6.37-2.27.24.1, 0.6.37-2.33.1
perl-solv - addressed in versions 0.6.37-2.27.24.1, 0.6.37-2.33.1
libsolv-devel-debuginfo - update to 0.6.37-2.33.1
python3-solv - update to 0.7.16-3
libsolv - update to 0.7.16-3
libzypp - addressed in versions 16.21.4-2.51.1, 16.21.4-27.75.1
libzypp-debuginfo - addressed in versions 16.21.4-2.51.1, 16.21.4-27.75.1
libzypp-debugsource - addressed in versions 16.21.4-2.51.1, 16.21.4-27.75.1
libzypp-devel - addressed in versions 16.21.4-2.51.1, 16.21.4-27.75.1
libzypp-devel-doc - update to 16.21.4-2.51.1
libsolv (Red Hat package) - update to 0.7.11-1.el8
Red Hat OpenShift Serverless - addressed in versions 1.10.2, 1.11.0, 1.12.0
Quay - update to 3.3.3
python-solv-debuginfo - addressed in versions 0.6.37-2.27.24.1, 0.6.37-2.33.1
libsolv-debugsource - addressed in versions 0.6.37-2.27.24.1, 0.6.37-2.33.1
libsolv-devel - addressed in versions 0.6.37-2.27.24.1, 0.6.37-2.33.1
libsolv-tools - addressed in versions 0.6.37-2.27.24.1, 0.6.37-2.33.1
libsolv-tools-debuginfo - addressed in versions 0.6.37-2.27.24.1, 0.6.37-2.33.1
python-solv - addressed in versions 0.6.37-2.27.24.1, 0.6.37-2.33.1
perl-solv-debuginfo - addressed in versions 0.6.37-2.27.24.1, 0.6.37-2.33.1
perl-solv - addressed in versions 0.6.37-2.27.24.1, 0.6.37-2.33.1
libsolv-devel-debuginfo - update to 0.6.37-2.33.1
python3-solv - update to 0.7.16-3
libsolv - update to 0.7.16-3
libzypp - addressed in versions 16.21.4-2.51.1, 16.21.4-27.75.1
libzypp-debuginfo - addressed in versions 16.21.4-2.51.1, 16.21.4-27.75.1
libzypp-debugsource - addressed in versions 16.21.4-2.51.1, 16.21.4-27.75.1
libzypp-devel - addressed in versions 16.21.4-2.51.1, 16.21.4-27.75.1
libzypp-devel-doc - update to 16.21.4-2.51.1
External References
Related Security Bulletins
- Denial of service in openSUSE libsolv
- Red Hat Enterprise Linux 8 update for libsolv
- Multiple vulnerabilities in Red Hat Openshift Serverless
- Multiple vulnerabilities in Red Hat OpenShift Container Storage
- Multiple vulnerabilities in Red Hat Quay
- Multiple vulnerabilities in Red Hat OpenShift Serverless
- Multiple vulnerabilities in Red Hat OpenShift Serverless
- SUSE update for libsolv
- SUSE update for libsolv
- Anolis OS update for libsolv