Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Libsolv: stack-based buffer overflow in libsolv eddsa pgp signature verification allows denial of service
Vulnerability Description
A flaw was found in libsolv. A stack-based buffer overflow vulnerability exists in the PGP verification component due to incorrect length handling when copying EdDSA 's' MPI into a stack buffer. A remote attacker could craft a malicious Ed25519 PGP signature with mismatched MPI lengths. Processing this crafted signature could lead to a denial of service in automated package or repository processing workflows.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Vulnerability Type
栈缓冲区溢出
Vulnerability Title
openSUSE libsolv 缓冲区错误漏洞
Vulnerability Description
openSUSE libsolv是openSUSE社区开源的一个检查软件包依赖的库。 openSUSE libsolv 0.7.38之前版本存在缓冲区错误漏洞,该漏洞源于PGP验证组件中复制EdDSA 's' MPI到堆栈缓冲区时长度处理不正确,存在栈缓冲区溢出漏洞,远程攻击者可制作恶意Ed25519 PGP签名,通过处理特制签名导致自动包或仓库处理工作流中的拒绝服务。
CVSS Information
N/A
Vulnerability Type
N/A