NULL Pointer Dereference in GNU recutils 1.8
CVE-2019-11638

6.5MEDIUM

Key Information:

Vendor
Gnu
Status
Vendor
CVE Published:
1 May 2019

Summary

A vulnerability exists in GNU recutils 1.8 due to a NULL pointer dereference in the rec_field_name_equal_p function found in rec-field-name.c within librec.a. This issue can lead to unexpected application crashes, potentially disrupting services and impacting user experiences. Attackers could exploit this flaw to compromise the application's stability.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.