Vulnerability Name:

CVE-2019-20367 (CCN-174253)

Assigned:2019-08-01
Published:2019-08-01
Updated:2021-04-01
Summary:nlist.c in libbsd before 0.10.0 has an out-of-bounds read during a comparison for a symbol name from the string table (strtab).
CVSS v3 Severity:9.1 Critical (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H)
7.9 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): None
Availibility (A): High
5.1 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L)
4.5 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): None
Availibility (A): Low
CVSS v2 Severity:6.4 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): Partial
3.6 Low (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:P)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): Partial
Vulnerability Type:CWE-125
Vulnerability Consequences:Denial of Service
References:Source: MITRE
Type: CNA
CVE-2019-20367

Source: SUSE
Type: Mailing List, Third Party Advisory
openSUSE-SU-2020:0679

Source: XF
Type: UNKNOWN
libbsd-cve201920367-dos(174253)

Source: CCN
Type: libbsd GIT Repository
nlist: Fix out-of-bounds read on strtab

Source: MISC
Type: Exploit, Vendor Advisory
https://gitlab.freedesktop.org/libbsd/libbsd/commit/9d917aad37778a9f4a96ba358415f077f3f36f3b

Source: MLIST
Type: UNKNOWN
[tomee-dev] 20210401 Re: CVE-2019-20367 - TomEE not affected

Source: MLIST
Type: UNKNOWN
[tomee-dev] 20210401 CVE-2019-20367 - TomEE not affected

Source: MLIST
Type: Mailing List, Third Party Advisory
[debian-lts-announce] 20210218 [SECURITY] [DLA 2566-1] libbsd security update

Source: MISC
Type: Mailing List, Release Notes, Vendor Advisory
https://lists.freedesktop.org/archives/libbsd/2019-August/000229.html

Source: UBUNTU
Type: Third Party Advisory
USN-4243-1

Vulnerable Configuration:Configuration 1:
  • cpe:/a:freedesktop:libbsd:*:*:*:*:*:*:*:* (Version < 0.10.0)

  • Configuration 2:
  • cpe:/o:debian:debian_linux:9.0:*:*:*:*:*:*:*

  • Configuration 3:
  • cpe:/o:canonical:ubuntu_linux:12.04:*:*:*:-:*:*:*
  • OR cpe:/o:canonical:ubuntu_linux:14.04:*:*:*:esm:*:*:*
  • OR cpe:/o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*
  • OR cpe:/o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
  • OR cpe:/o:canonical:ubuntu_linux:19.04:*:*:*:*:*:*:*

  • Configuration 4:
  • cpe:/o:opensuse:leap:15.1:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:libbsd:libbsd:*:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:201920367
    V
    CVE-2019-20367
    2023-06-22
    oval:org.opensuse.security:def:7580
    P
    libbsd-devel-0.8.7-3.3.17 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:719
    P
    Security update for gstreamer-plugins-good (Important)
    2022-08-31
    oval:org.opensuse.security:def:3649
    P
    Security update for u-boot (Important) (in QA)
    2022-08-04
    oval:org.opensuse.security:def:3661
    P
    Security update for keylime (Important)
    2022-08-03
    oval:org.opensuse.security:def:3011
    P
    apache2-mod_apparmor-2.8.2-51.18.3 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3009
    P
    apache-commons-httpclient-3.1-4.364 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3001
    P
    PackageKit-1.1.3-24.9.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:2924
    P
    fuse-2.9.7-3.3.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:94627
    P
    libbsd-devel-0.8.7-3.3.17 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:2930
    P
    ghostscript-9.52-161.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:2942
    P
    groff-1.22.4-150400.3.4 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:2956
    P
    java-11-openjdk-11.0.15.0-150000.3.80.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:2962
    P
    keylime-agent-6.3.0-150400.2.5 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:2971
    P
    libQt5Concurrent-devel-5.15.2+kde294-150400.4.8 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:2997
    P
    libbsd-devel-0.8.7-3.3.17 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:2920
    P
    firewalld-0.9.3-150400.7.6 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:2995
    P
    libblkid-devel-2.37.2-150400.6.26 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:123
    P
    libbsd-devel-0.8.7-3.3.17 on GA media (Moderate)
    2022-06-13
    oval:org.opensuse.security:def:1668
    P
    Security update for libslirp (Important)
    2022-05-18
    oval:org.opensuse.security:def:1052
    P
    Security update for fetchmail (Moderate)
    2021-12-14
    oval:org.opensuse.security:def:64631
    P
    Security update for glib-networking (Important)
    2021-12-06
    oval:org.opensuse.security:def:93775
    P
    (Moderate)
    2021-12-03
    oval:org.opensuse.security:def:49456
    P
    Security update for php72 (Moderate)
    2021-11-19
    oval:org.opensuse.security:def:68303
    P
    Security update for the Linux Kernel (Live Patch 16 for SLE 15 SP2) (Important)
    2021-11-17
    oval:org.opensuse.security:def:64801
    P
    Security update for the Linux Kernel (Important)
    2021-11-16
    oval:org.opensuse.security:def:74743
    P
    Security update for binutils (Moderate)
    2021-11-09
    oval:org.opensuse.security:def:69706
    P
    Security update for webkit2gtk3 (Important)
    2021-08-17
    oval:org.opensuse.security:def:48185
    P
    libquicktime0-1.2.4-14.3.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48186
    P
    libraptor2-0-2.0.10-3.63 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48200
    P
    libssh2-1-1.4.3-20.9.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48321
    P
    tar-1.27.1-15.3.7 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:63377
    P
    squid-4.13-5.23.1 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:71882
    P
    libbsd-devel-0.8.7-3.3.17 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:100899
    P
    libbsd-devel-0.8.7-3.3.17 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:62141
    P
    libbsd-devel-0.8.7-3.3.17 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:68203
    P
    Security update for the Linux Kernel (Live Patch 9 for SLE 15 SP2) (Important)
    2021-07-15
    oval:org.opensuse.security:def:68805
    P
    Security update for the Linux Kernel (Important)
    2021-06-30
    oval:org.opensuse.security:def:64529
    P
    Security update for postgresql12 (Moderate)
    2021-06-17
    oval:org.opensuse.security:def:62874
    P
    perl-Tk-devel-804.034-1.44 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48514
    P
    libksba8-1.3.0-23.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:62878
    P
    subversion-bash-completion-1.10.0-1.24 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48646
    P
    wireshark-1.12.13-31.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48738
    P
    libmysqlclient_r18-10.0.21-1.17 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:62881
    P
    zlib-devel-32bit-1.2.11-1.422 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48886
    P
    telepathy-gabble-0.18.3-5.7 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:64689
    P
    Security update for graphviz (Critical)
    2021-05-19
    oval:org.opensuse.security:def:52032
    P
    Security update for tomcat (Important)
    2021-03-30
    oval:org.opensuse.security:def:69811
    P
    Security update for libass (Important)
    2021-03-24
    oval:org.opensuse.security:def:65561
    P
    Security update for openldap2 (Moderate)
    2021-01-14
    oval:org.opensuse.security:def:49438
    P
    Security update for nodejs14 (Moderate)
    2021-01-13
    oval:org.opensuse.security:def:72261
    P
    libXrandr2-32bit-1.5.1-2.17 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:63580
    P
    icedtea-web-1.7.1-5.13 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:71543
    P
    libXvMC-devel-1.0.10-1.23 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:107154
    P
    libbsd-devel-0.8.7-3.3.17 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:116712
    P
    libbsd-devel-0.8.7-3.3.17 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:100488
    P
    libbsd-devel-0.8.7-3.3.17 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:2306
    P
    apache-commons-beanutils-1.9.2-2.46 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:72145
    P
    libXi6-32bit-1.7.9-1.23 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:61808
    P
    libbsd-devel-0.8.7-3.3.17 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62906
    P
    libtidy-devel-5.4.0-1.34 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:71656
    P
    libykcs11-1-1.6.2-4.30 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:71549
    P
    libbsd-devel-0.8.7-3.3.17 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:63084
    P
    libopenssl-1_0_0-devel-1.0.2p-3.25.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:49100
    P
    ghostscript on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:65471
    P
    Security update for dhcp (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50032
    P
    salt-api on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50743
    P
    Security update for libbsd (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49184
    P
    libksba-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50189
    P
    gstreamer-plugins-ugly on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50689
    P
    Security update for python3 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:63727
    P
    Security update for postgresql10 (Important)
    2020-12-01
    oval:org.opensuse.security:def:49342
    P
    tar on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:66455
    P
    libbsd-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:73146
    P
    libbsd-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49437
    P
    libgnomesu on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50427
    P
    Security update for glibc (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:66363
    P
    collectd on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:63956
    P
    Security update for xen (Important)
    2020-12-01
    oval:org.opensuse.security:def:49413
    P
    gtk2-data on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49311
    P
    python3-Werkzeug on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:52094
    P
    Security update for libbsd (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50517
    P
    Security update for postgresql (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:74876
    P
    Security update for libbsd (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64285
    P
    kdump on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50683
    P
    Security update for python (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49246
    P
    libtiff-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64421
    P
    openslp on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50756
    P
    Security update for java-11-openjdk (Important)
    2020-12-01
    oval:org.opensuse.security:def:49583
    P
    libvdpau-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50652
    P
    Security update for podman, slirp4netns and libcontainers-common (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64956
    P
    Security update for libbsd (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64422
    P
    openssh on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64869
    P
    Security update for python-urllib3 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:73028
    P
    Mesa on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49788
    P
    libgit2-26 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:68908
    P
    Security update for libbsd (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50587
    P
    Security update for git (Important)
    2020-12-01
    oval:org.opensuse.security:def:49160
    P
    libbsd-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49106
    P
    glibc-locale-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49934
    P
    389-ds on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:110538
    P
    Security update for libbsd (Moderate)
    2020-05-22
    oval:org.opensuse.security:def:97892
    P
    Security update for libbsd (Moderate)
    2020-05-18
    oval:org.opensuse.security:def:90282
    P
    Security update for libbsd (Moderate)
    2020-05-18
    oval:org.opensuse.security:def:75288
    P
    Security update for libbsd (Moderate)
    2020-05-18
    oval:org.opensuse.security:def:90927
    P
    Security update for libbsd (Moderate)
    2020-05-18
    oval:org.opensuse.security:def:99859
    P
    (Moderate)
    2020-05-18
    oval:org.opensuse.security:def:103937
    P
    Security update for libbsd (Moderate)
    2020-05-18
    oval:org.opensuse.security:def:100196
    P
    (Moderate)
    2020-05-18
    oval:org.opensuse.security:def:104582
    P
    Security update for libbsd (Moderate)
    2020-05-18
    oval:com.ubuntu.disco:def:2019203670000000
    V
    CVE-2019-20367 on Ubuntu 19.04 (disco) - medium.
    2020-01-08
    oval:com.ubuntu.bionic:def:2019203670000000
    V
    CVE-2019-20367 on Ubuntu 18.04 LTS (bionic) - medium.
    2020-01-08
    oval:com.ubuntu.xenial:def:2019203670000000
    V
    CVE-2019-20367 on Ubuntu 16.04 LTS (xenial) - medium.
    2020-01-08
    BACK
    freedesktop libbsd *
    debian debian linux 9.0
    canonical ubuntu linux 12.04
    canonical ubuntu linux 14.04
    canonical ubuntu linux 16.04
    canonical ubuntu linux 18.04
    canonical ubuntu linux 19.04
    opensuse leap 15.1
    libbsd libbsd *