Memory Access Flaw in libyang Affects CESNET Software
CVE-2019-20391
6.5MEDIUM
What is CVE-2019-20391?
A memory access flaw exists in libyang versions prior to v1.0-r3, specifically within the resolve_feature_value() function when processing if-feature statements inside bit definitions. This vulnerability can lead to application crashes when libyang is utilized to parse untrusted YANG files, posing a significant risk to systems relying on this library for configuration management.
