← Back

CVE-2019-19334

nvd nist
Published: Dec 6, 2019Modified: Nov 21, 2024

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

In all versions of libyang before 1.0-r5, a stack-based buffer overflow was discovered in the way libyang parses YANG files with a leaf of type "identityref". An application that uses libyang to parse untrusted YANG files may be vulnerable to this flaw, which would allow an attacker to cause a denial of service or possibly gain code execution.

Affected (17)

1 product
Libyang
1 product
Enterprise Linux
1 product
Fedora
Configuration A
15 vulnerable
Vulnerable SoftwareAffected Versions
Cesnet
Version 0.11 r1
Version 0.11 r2
Version 0.12 r1
Version 0.12 r2
Version 0.13 r1
Version 0.13 r2
Version 0.14 r1
Version 0.15 r1
Version 0.16 r1
Version 0.16 r2
Version 0.16 r3
Version 1.0 r1
Version 1.0 r2
Version 1.0 r3
Version 1.0 r4
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 8.0
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 31

Timeline

No history available yet.