Opensuse

Libsolv

14 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.47%
  • Veröffentlicht 16.07.2026 00:46:12
  • Zuletzt bearbeitet 18.07.2026 03:16:36

A flaw was found in libsolv. A stack-based buffer overflow vulnerability exists in the PGP verification component due to incorrect length handling when copying EdDSA 's' MPI into a stack buffer. A remote attacker could craft a malicious Ed25519 PGP s...

Exploit
  • EPSS 0.23%
  • Veröffentlicht 26.05.2026 16:16:07
  • Zuletzt bearbeitet 11.08.2026 10:17:12

A flaw was found in libsolv. This heap buffer overflow occurs during the decompression of attacker-controlled compressed data within `.solv` files due to insufficient input validation. An attacker can provide a specially crafted `.solv` file, which, ...

  • EPSS 0.31%
  • Veröffentlicht 20.05.2026 23:34:56
  • Zuletzt bearbeitet 31.07.2026 18:17:37

A flaw was found in libsolv. This heap buffer overflow vulnerability occurs when a victim processes a specially crafted `.solv` file containing negative size values in the `repo_add_solv` function. This leads to an undersized memory allocation and a ...

  • EPSS 0.41%
  • Veröffentlicht 20.05.2026 23:16:36
  • Zuletzt bearbeitet 31.07.2026 18:17:38

A flaw was found in libsolv. This stack-based buffer overflow vulnerability occurs in libsolv's Debian metadata parser when processing specially crafted Debian repository metadata. An attacker could exploit this by providing malicious SHA384 or SHA51...

Exploit
  • EPSS 1.79%
  • Veröffentlicht 21.02.2022 18:15:08
  • Zuletzt bearbeitet 21.11.2024 06:31:13

Two heap-overflow vulnerabilities exist in openSUSE/libsolv libsolv through 13 Dec 2020 in the decisionmap variable via the resolve_dependencies function at src/solver.c (line 1940 & line 1995), which could cause a remote Denial of Service.

Exploit
  • EPSS 1.46%
  • Veröffentlicht 02.09.2021 15:15:07
  • Zuletzt bearbeitet 21.11.2024 06:09:46

Buffer overflow vulnerability in function pool_installable in src/repo.h in libsolv before 0.7.17 allows attackers to cause a Denial of Service.

Exploit
  • EPSS 1.44%
  • Veröffentlicht 02.09.2021 15:15:07
  • Zuletzt bearbeitet 21.11.2024 06:09:47

Buffer overflow vulnerability in function pool_disabled_solvable in src/repo.h in libsolv before 0.7.17 allows attackers to cause a Denial of Service.

Exploit
  • EPSS 1.46%
  • Veröffentlicht 02.09.2021 15:15:07
  • Zuletzt bearbeitet 21.11.2024 06:09:47

Buffer overflow vulnerability in function pool_installable_whatprovides in src/repo.h in libsolv before 0.7.17 allows attackers to cause a Denial of Service.

Exploit
  • EPSS 1.42%
  • Veröffentlicht 02.09.2021 15:15:07
  • Zuletzt bearbeitet 21.11.2024 06:09:47

Buffer overflow vulnerability in function prune_to_recommended in src/policy.c in libsolv before 0.7.17 allows attackers to cause a Denial of Service.

Exploit
  • EPSS 1.31%
  • Veröffentlicht 18.05.2021 17:15:07
  • Zuletzt bearbeitet 21.11.2024 06:21:08

Buffer overflow vulnerability in libsolv 2020-12-13 via the Solver * testcase_read(Pool *pool, FILE *fp, const char *testcase, Queue *job, char **resultp, int *resultflagsp function at src/testcase.c: line 2334, which could cause a denial of service