CVE-2021-33930 is a buffer overflow vulnerability in the libsolv library, specifically within the pool_installable_whatprovides function, affecting openSUSE libsolv versions prior to 0.7.17. This flaw carries a CVSSv3 score of 7.5 (High), indicating it can be exploited remotely with low attack complexity, requiring no user interaction, to cause a Denial of Service. While the vulnerability is significant, there is currently no evidence of active exploitation, publicly available exploit code (Metasploit, Nuclei, ExploitDB), or community discussion surrounding it.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.7.17CPE matchmatch criteria | cpe:2.3:a:opensuse:libsolv:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Buffer overflow vulnerability in function pool_installable_whatprovides in src/repo.h in libsolv before 0.7.17 allows attackers to cause a Denial of Service.
Sep 14, 2021libsolv: heap-based buffer overflow in pool_installable_whatprovides() in src/repo.h
Dec 13, 2020