CVE-2021-33928 is a buffer overflow vulnerability in the pool_installable function of libsolv versions prior to 0.7.17, specifically affecting opensuse libsolv. This vulnerability carries a CVSS score of 7.5 (HIGH), indicating it can be exploited remotely with low attack complexity to cause a Denial of Service. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.7.17CPE matchmatch criteria | cpe:2.3:a:opensuse:libsolv:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Buffer overflow vulnerability in function pool_installable in src/repo.h in libsolv before 0.7.17 allows attackers to cause a Denial of Service.
Sep 14, 2021libsolv: heap-based buffer overflow in pool_installable() in src/repo.h
Dec 13, 2020