rpm package
suse/libcomps&distro=SUSE Package Hub 15
pkg:rpm/suse/libcomps&distro=SUSE%20Package%20Hub%2015
Vulnerabilities (1)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2019-3817 | Hig | 7.5 | < 0.1.8-bp150.3.3.1 | 0.1.8-bp150.3.3.1 | Mar 27, 2019 | A use-after-free flaw has been discovered in libcomps before version 0.1.10 in the way ObjMRTrees are merged. An attacker, who is able to make an application read a crafted comps XML file, may be able to crash the application or execute malicious code. |
- affected < 0.1.8-bp150.3.3.1fixed 0.1.8-bp150.3.3.1
A use-after-free flaw has been discovered in libcomps before version 0.1.10 in the way ObjMRTrees are merged. An attacker, who is able to make an application read a crafted comps XML file, may be able to crash the application or execute malicious code.