Related Vulnerabilities: CVE-2021-44570  

Two heap-overflow vulnerabilities exists in openSUSE/libsolv through 13 Dec 2020 in the bugs in the solver_get_recommendations funtion function at src/solver.c: line 4286 & line 4305 FOR_PROVIDES.

Description

The MITRE CVE dictionary describes this issue as:

Two heap-overflow vulnerabilities exists in openSUSE/libsolv through 13 Dec 2020 in the bugs in the solver_get_recommendations funtion function at src/solver.c: line 4286 & line 4305 FOR_PROVIDES.

Additional Information

  • Bugzilla 2056794: CVE-2021-44570 libsolv: Heap overflow
  • CWE-787: Out-of-bounds Write
  • FAQ: Frequently asked questions about CVE-2021-44570