MEDIUM
bison: Buffer overflow in src/symtab.c via crafted input file redefining the EOF token can lead to DoS
Published Sep 4, 2020
5.5
MEDIUMCVSS 3.1
EPSS 0.24%
Description
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none
Affected products
No data.
No data.
No data.
Red Hat Enterprise Linux 5
bison
Out of support scope
Red Hat Enterprise Linux 6
bison
Out of support scope
Red Hat Enterprise Linux 7
bison
Will not fix
Red Hat Enterprise Linux 8
bison
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | bison | Out of support scope | n/a |
| Red Hat Enterprise Linux 6 | bison | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | bison | Will not fix | n/a |
| Red Hat Enterprise Linux 8 | bison | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Please note that this CVE has been rejected Upstream.
Red Hat mitigation
This flaw can be mitigated by not supplying untrusted input to be processed by GNU Bison.
Weaknesses (1)
References (5)
- https://access.redhat.com/security/cve/CVE-2020-24979 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1877772 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-17679 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-24979
- https://www.cve.org/CVERecord?id=CVE-2020-24979
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status n/a
Assigner n/a
Published Sep 4, 2020
Updated n/a
Reserved n/a
Link CVE-2020-24979
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2020-17679 Assigner mitre
Published Sep 3, 2020
Updated Sep 14, 2020
Exploited since n/a
Link EUVD-2020-17679