Heap-Based Buffer Over-Read in libsolv Affects openSUSE Products
CVE-2019-20387
7.5HIGH
What is CVE-2019-20387?
The vulnerability in libsolv prior to version 0.7.6 allows an attacker to trigger a heap-based buffer over-read. This occurs through exploiting a last schema whose length is less than that of the input schema, potentially leading to information disclosure. Users of openSUSE and other products relying on this library should apply the necessary updates to mitigate the risks associated with this flaw.