ALAS2-2019-1374

Related Vulnerabilities: CVE-2018-20532   CVE-2018-20533   CVE-2018-20534  

There is an illegal address access at ext/testcase.c in libsolv.a in libsolv through 0.7.2 that will cause a denial of service. NOTE: third parties dispute this issue stating that the issue affects the test suite and not the underlying library. It cannot be exploited in any real-world application.(CVE-2018-20534) There is a NULL pointer dereference at ext/testcase.c (function testcase_read) in libsolvext.a in libsolv through 0.7.2 that will cause a denial of service.(CVE-2018-20532) There is a NULL pointer dereference at ext/testcase.c (function testcase_str2dep_complex) in libsolvext.a in libsolv through 0.7.2 that will cause a denial of service.(CVE-2018-20533)

ALAS2-2019-1374


Amazon Linux 2 Security Advisory: ALAS-2019-1374
Advisory Release Date: 2019-12-13 19:36 Pacific
Advisory Updated Date: 2019-12-18 01:27 Pacific
Severity: Low

Issue Overview:

There is an illegal address access at ext/testcase.c in libsolv.a in libsolv through 0.7.2 that will cause a denial of service. NOTE: third parties dispute this issue stating that the issue affects the test suite and not the underlying library. It cannot be exploited in any real-world application.(CVE-2018-20534)

There is a NULL pointer dereference at ext/testcase.c (function testcase_read) in libsolvext.a in libsolv through 0.7.2 that will cause a denial of service.(CVE-2018-20532)

There is a NULL pointer dereference at ext/testcase.c (function testcase_str2dep_complex) in libsolvext.a in libsolv through 0.7.2 that will cause a denial of service.(CVE-2018-20533)


Affected Packages:

libsolv


Issue Correction:
Run yum update libsolv to update your system.

New Packages:
aarch64:
    libsolv-0.6.34-4.amzn2.aarch64
    libsolv-devel-0.6.34-4.amzn2.aarch64
    libsolv-tools-0.6.34-4.amzn2.aarch64
    libsolv-demo-0.6.34-4.amzn2.aarch64
    python2-solv-0.6.34-4.amzn2.aarch64
    libsolv-debuginfo-0.6.34-4.amzn2.aarch64

i686:
    libsolv-0.6.34-4.amzn2.i686
    libsolv-devel-0.6.34-4.amzn2.i686
    libsolv-tools-0.6.34-4.amzn2.i686
    libsolv-demo-0.6.34-4.amzn2.i686
    python2-solv-0.6.34-4.amzn2.i686
    libsolv-debuginfo-0.6.34-4.amzn2.i686

src:
    libsolv-0.6.34-4.amzn2.src

x86_64:
    libsolv-0.6.34-4.amzn2.x86_64
    libsolv-devel-0.6.34-4.amzn2.x86_64
    libsolv-tools-0.6.34-4.amzn2.x86_64
    libsolv-demo-0.6.34-4.amzn2.x86_64
    python2-solv-0.6.34-4.amzn2.x86_64
    libsolv-debuginfo-0.6.34-4.amzn2.x86_64