5
CVSSv2

CVE-2021-28903

Published: 20/05/2021 Updated: 05/04/2022
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

A stack overflow in libyang <= v1.0.225 can cause a denial of service through function lyxml_parse_mem(). lyxml_parse_elem() function will be called recursively, which will consume stack space and lead to crash.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cesnet libyang

Vendor Advisories

Debian Bug report logs - #989060 CVE-2021-28902 CVE-2021-28903 CVE-2021-28904 CVE-2021-28905 CVE-2021-28906 Package: src:libyang; Maintainer for src:libyang is David Lamparter &lt;equinox-debian@diac24net&gt;; Reported by: Moritz Muehlenhoff &lt;jmm@debianorg&gt; Date: Mon, 24 May 2021 20:51:02 UTC Severity: important Tags: se ...