« Volver al listado

CVE-2019-20398

Estado: ModificadaMedia (6.5)—

A NULL pointer dereference is present in libyang before v1.0-r3 in the function lys_extension_instances_free() due to a copy of unresolved extensions in lys_restr_dup(). Applications that use libyang to parse untrusted input yang files may crash.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2019-20398",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:N/I:N/A:P",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2020-01-22T22:15:10.627",
  "references": [
    {
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1793935",
      "tags": [
        "Issue Tracking",
        "Patch",
        "Third Party Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://github.com/CESNET/libyang/commit/7852b272ef77f8098c35deea6c6f09cb78176f08",
      "tags": [
        "Patch"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://github.com/CESNET/libyang/compare/v1.0-r2...v1.0-r3",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://github.com/CESNET/libyang/issues/773",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://lists.debian.org/debian-lts-announce/2023/09/msg00019.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1793935",
      "tags": [
        "Issue Tracking",
        "Patch",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://github.com/CESNET/libyang/commit/7852b272ef77f8098c35deea6c6f09cb78176f08",
      "tags": [
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://github.com/CESNET/libyang/compare/v1.0-r2...v1.0-r3",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://github.com/CESNET/libyang/issues/773",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://lists.debian.org/debian-lts-announce/2023/09/msg00019.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-476"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A NULL pointer dereference is present in libyang before v1.0-r3 in the function lys_extension_instances_free() due to a copy of unresolved extensions in lys_restr_dup(). Applications that use libyang to parse untrusted input yang files may crash."
    },
    {
      "lang": "es",
      "value": "Una desreferencia del puntero NULL está presente en libyang versiones anteriores a v1.0-r3, en la función lys_extension_instances_free() debido a una copia de extensiones no resuelta en la función lys_restr_dup(). Las aplicaciones que usan libyang para analizar archivos de entrada yang no confiables pueden bloquearse."
    }
  ],
  "lastModified": "2026-06-17T02:30:21.860",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:cesnet:libyang:0.11:r1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "65E91322-5F67-43C2-8112-5ECAEC2A3C12"
            },
            {
              "criteria": "cpe:2.3:a:cesnet:libyang:0.11:r2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "80A88DE4-93F8-40C3-AA52-A5F353F028AA"
            },
            {
              "criteria": "cpe:2.3:a:cesnet:libyang:0.12:r1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "05C120CA-50EF-4B6D-92C9-ED736219DB07"
            },
            {
              "criteria": "cpe:2.3:a:cesnet:libyang:0.12:r2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "99D1FA55-3F56-4E09-B41E-B05C199B96B8"
            },
            {
              "criteria": "cpe:2.3:a:cesnet:libyang:0.13:r1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "35D48EC4-58D2-49C6-8049-920787733587"
            },
            {
              "criteria": "cpe:2.3:a:cesnet:libyang:0.13:r2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B57F3953-49D6-413C-A4AE-03125935FC77"
            },
            {
              "criteria": "cpe:2.3:a:cesnet:libyang:0.14:r1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DD62411F-A524-4E80-B540-780EA39CB6A4"
            },
            {
              "criteria": "cpe:2.3:a:cesnet:libyang:0.15:r1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FEF091B1-978A-4881-B1FC-6848CD1A7BBF"
            },
            {
              "criteria": "cpe:2.3:a:cesnet:libyang:0.16:r1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0C50D690-9A4D-4B78-BF4E-A4D9B4074216"
            },
            {
              "criteria": "cpe:2.3:a:cesnet:libyang:0.16:r2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "124A5D30-7451-4516-9AA2-963AE62DD679"
            },
            {
              "criteria": "cpe:2.3:a:cesnet:libyang:0.16:r3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C260D13B-82E9-4596-9116-61073B42D661"
            },
            {
              "criteria": "cpe:2.3:a:cesnet:libyang:1.0:r1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5F8D5FC0-959E-4014-9CB7-91378CC8B2BA"
            },
            {
              "criteria": "cpe:2.3:a:cesnet:libyang:1.0:r2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DCBDA519-805B-4193-8092-75E2748A7BC3"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}