605
VMScore

CVE-2019-20394

Published: 22/01/2020 Updated: 19/09/2023
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

A double-free is present in libyang before v1.0-r3 in the function yyparse() when a type statement in used in a notification statement. Applications that use libyang to parse untrusted input yang files may be vulnerable to this flaw, which would cause a crash or potentially code execution.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cesnet libyang 1.0

cesnet libyang 0.16

cesnet libyang 0.13

cesnet libyang 0.12

cesnet libyang 0.11

cesnet libyang 0.14

cesnet libyang 0.15