Double-Free Vulnerability in libyang Affects Multiple Applications
CVE-2019-20397

8.8HIGH

Key Information:

Vendor

Cesnet

Status
Vendor
CVE Published:
22 January 2020

What is CVE-2019-20397?

The vulnerability in libyang occurs due to a double-free error in the yyparse() function when an organization field is not properly terminated. This flaw can lead to applications that utilize libyang for parsing untrusted yang files experiencing unexpected crashes or, in some cases, allowing for code execution by an attacker. As such, it poses a significant risk to the stability and security of affected applications.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.