Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Libsolv: heap buffer overflow in libsolv repopagestore via unchecked decompression of malicious .solv page data
Vulnerability Description
A flaw was found in libsolv. This heap buffer overflow occurs during the decompression of attacker-controlled compressed data within `.solv` files due to insufficient input validation. An attacker can provide a specially crafted `.solv` file, which, when processed by a vulnerable application, can lead to out-of-bounds memory access. This could result in information disclosure, alteration of program execution, or a denial of service.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Vulnerability Type
跨界内存写
Vulnerability Title
libsolv 安全漏洞
Vulnerability Description
libsolv是openSUSE开源的一个用于检查软件包依赖的库。 libsolv存在安全漏洞,该漏洞源于解压攻击者控制的压缩数据时输入验证不足,导致堆缓冲区溢出,可能导致信息泄露、程序执行更改或拒绝服务。
CVSS Information
N/A
Vulnerability Type
N/A