libcomps: use after free when merging two objmrtrees
Published Mar 27, 2019
8.8
HIGHCVSS 3.0
EPSS 1.72%
Description
A use-after-free flaw has been discovered in libcomps before version 0.1.10 in the way ObjMRTrees are merged. An attacker, who is able to make an application read a crafted comps XML file, may be able to crash the application or execute malicious code.
Affected products
-
- Version 0.1.10StatusaffectedConstraints-
- Version
No data.
Red Hat Enterprise Linux 7 Extras
libcomps-0:0.1.8-13.el7
Fixed · RHSA-2019:3898
Red Hat Enterprise Linux 8
createrepo_c-0:0.11.0-3.el8
Fixed · RHSA-2019:3583
Red Hat Enterprise Linux 8
createrepo_c-0:0.11.0-3.el8
Fixed · RHSA-2019:3583
Red Hat Enterprise Linux 8
dnf-0:4.2.7-6.el8
Fixed · RHSA-2019:3583
Red Hat Enterprise Linux 8
dnf-0:4.2.7-6.el8
Fixed · RHSA-2019:3583
Red Hat Enterprise Linux 8
dnf-plugins-core-0:4.0.8-3.el8
Fixed · RHSA-2019:3583
Red Hat Enterprise Linux 8
dnf-plugins-core-0:4.0.8-3.el8
Fixed · RHSA-2019:3583
Red Hat Enterprise Linux 8
libcomps-0:0.1.11-2.el8
Fixed · RHSA-2019:3583
Red Hat Enterprise Linux 8
libcomps-0:0.1.11-2.el8
Fixed · RHSA-2019:3583
Red Hat Enterprise Linux 8
libdnf-0:0.35.1-8.el8
Fixed · RHSA-2019:3583
Red Hat Enterprise Linux 8
libdnf-0:0.35.1-8.el8
Fixed · RHSA-2019:3583
Red Hat Enterprise Linux 8
librepo-0:1.10.3-3.el8
Fixed · RHSA-2019:3583
Red Hat Enterprise Linux 8
librepo-0:1.10.3-3.el8
Fixed · RHSA-2019:3583
Red Hat Enterprise Linux 8
librhsm-0:0.0.3-3.el8
Fixed · RHSA-2019:3583
Red Hat Enterprise Linux 8
librhsm-0:0.0.3-3.el8
Fixed · RHSA-2019:3583
Red Hat Enterprise Linux 8
libsolv-0:0.7.4-3.el8
Fixed · RHSA-2019:3583
Red Hat Enterprise Linux 8
libsolv-0:0.7.4-3.el8
Fixed · RHSA-2019:3583
Red Hat Enterprise Linux 8
microdnf-0:3.0.1-3.el8
Fixed · RHSA-2019:3583
Red Hat Enterprise Linux 8
microdnf-0:3.0.1-3.el8
Fixed · RHSA-2019:3583
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 Extras | libcomps-0:0.1.8-13.el7 | Fixed | RHSA-2019:3898 |
| Red Hat Enterprise Linux 8 | createrepo_c-0:0.11.0-3.el8 | Fixed | RHSA-2019:3583 |
| Red Hat Enterprise Linux 8 | createrepo_c-0:0.11.0-3.el8 | Fixed | RHSA-2019:3583 |
| Red Hat Enterprise Linux 8 | dnf-0:4.2.7-6.el8 | Fixed | RHSA-2019:3583 |
| Red Hat Enterprise Linux 8 | dnf-0:4.2.7-6.el8 | Fixed | RHSA-2019:3583 |
| Red Hat Enterprise Linux 8 | dnf-plugins-core-0:4.0.8-3.el8 | Fixed | RHSA-2019:3583 |
| Red Hat Enterprise Linux 8 | dnf-plugins-core-0:4.0.8-3.el8 | Fixed | RHSA-2019:3583 |
| Red Hat Enterprise Linux 8 | libcomps-0:0.1.11-2.el8 | Fixed | RHSA-2019:3583 |
| Red Hat Enterprise Linux 8 | libcomps-0:0.1.11-2.el8 | Fixed | RHSA-2019:3583 |
| Red Hat Enterprise Linux 8 | libdnf-0:0.35.1-8.el8 | Fixed | RHSA-2019:3583 |
| Red Hat Enterprise Linux 8 | libdnf-0:0.35.1-8.el8 | Fixed | RHSA-2019:3583 |
| Red Hat Enterprise Linux 8 | librepo-0:1.10.3-3.el8 | Fixed | RHSA-2019:3583 |
| Red Hat Enterprise Linux 8 | librepo-0:1.10.3-3.el8 | Fixed | RHSA-2019:3583 |
| Red Hat Enterprise Linux 8 | librhsm-0:0.0.3-3.el8 | Fixed | RHSA-2019:3583 |
| Red Hat Enterprise Linux 8 | librhsm-0:0.0.3-3.el8 | Fixed | RHSA-2019:3583 |
| Red Hat Enterprise Linux 8 | libsolv-0:0.7.4-3.el8 | Fixed | RHSA-2019:3583 |
| Red Hat Enterprise Linux 8 | libsolv-0:0.7.4-3.el8 | Fixed | RHSA-2019:3583 |
| Red Hat Enterprise Linux 8 | microdnf-0:3.0.1-3.el8 | Fixed | RHSA-2019:3583 |
| Red Hat Enterprise Linux 8 | microdnf-0:3.0.1-3.el8 | Fixed | RHSA-2019:3583 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (10)
- https://access.redhat.com/errata/RHSA-2019:3583 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2019:3898 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2019-3817 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1668005 Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3817 x_refsource_CONFIRMExploitIssue TrackingVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-13440 Advisory
- https://github.com/rpm-software-management/libcomps/commit/e3a5d056633677959ad924a51758876d415e7046 x_refsource_CONFIRMPatchThird Party Advisory
- https://github.com/rpm-software-management/libcomps/issues/41 x_refsource_CONFIRMExploitIssue TrackingThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-3817
- https://www.cve.org/CVERecord?id=CVE-2019-3817
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2019:3583 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/errata/RHSA-2019:3898 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/security/cve/CVE-2019-3817 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1668005 | Issue Tracking | |
| https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3817 | x_refsource_CONFIRMExploitIssue TrackingVendor Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-13440 | Advisory | |
| https://github.com/rpm-software-management/libcomps/commit/e3a5d056633677959ad924a51758876d415e7046 | x_refsource_CONFIRMPatchThird Party Advisory | |
| https://github.com/rpm-software-management/libcomps/issues/41 | x_refsource_CONFIRMExploitIssue TrackingThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2019-3817 | ||
| https://www.cve.org/CVERecord?id=CVE-2019-3817 |
Change history (0)
No recorded changes yet.