Out-of-bounds write in libsolv - CVE-2021-44568

 

Out-of-bounds write in libsolv - CVE-2021-44568

Published: August 12, 2022


Vulnerability identifier: #VU66439
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-44568
CWE-ID: CWE-787
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary error when processing untrusted input within the resolve_dependencies() function at src/solver.c. A remote attacker can create a specially crafted file, trick the victim into opening it using the affected software, trigger an out-of-bounds write and crash the application.

Affected software

libsolv
openEuler
Business Automation Insights
IBM Cloud Pak for Business Automation
libsolv
libsolv-debuginfo
libsolv-debugsource
ruby-solv
python3-solv
perl-solv
libsolv-devel
libsolv-help
Dell EMC Container Storage Modules

How to mitigate CVE-2021-44568

Install updates from vendor's website.

libsolv - update to 0.7.17
Business Automation Insights - addressed in versions 24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2
IBM Cloud Pak for Business Automation - addressed in versions 24.0.1-IF006, 25.0.0-IF003
libsolv - update to 0.7.14-5
libsolv-debuginfo - update to 0.7.14-5
libsolv-debugsource - update to 0.7.14-5
ruby-solv - update to 0.7.14-5
python3-solv - update to 0.7.14-5
perl-solv - update to 0.7.14-5
libsolv-devel - update to 0.7.14-5
libsolv-help - update to 0.7.14-5
Dell EMC Container Storage Modules - update to 1.7.0

External References

Related Security Bulletins