Bug 1134071 - (CVE-2019-11637) VUL-1: CVE-2019-11637: gnu-recutils: NULL pointer dereference in the function rec_rset_get_props
(CVE-2019-11637)
VUL-1: CVE-2019-11637: gnu-recutils: NULL pointer dereference in the function...
Status: RESOLVED INVALID
Classification: openSUSE
Product: openSUSE Distribution
Classification: openSUSE
Component: Security
Leap 15.0
Other Other
: P4 - Low : Normal (vote)
: ---
Assigned To: Security Team bot
Security Team bot
https://smash.suse.de/issue/231888/
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2019-05-03 14:45 UTC by Alexander Bergmann
Modified: 2020-01-16 15:26 UTC (History)
1 user (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Alexander Bergmann 2019-05-03 14:45:54 UTC
CVE-2019-11637:
An issue was discovered in GNU recutils 1.8. There is a NULL pointer dereference in the function rec_rset_get_props at rec-rset.c in librec.a, leading to a crash.

References:
https://github.com/TeamSeri0us/pocs/blob/master/recutils/bug-report-recutils/
https://github.com/TeamSeri0us/pocs/tree/master/recutils/bug-report-recutils/recfix
https://github.com/TeamSeri0us/pocs/tree/master/recutils/bug-report-recutils/rec2csv
Comment 1 Wolfgang Frisch 2020-01-16 15:26:34 UTC
This package was dropped after Leap 15.0.
Closing.