CVE-2021-3200 is a low-severity buffer overflow vulnerability in libsolv, specifically affecting versions from 2020-12-13, and impacting products like openSUSE and Oracle Communications Cloud Native Core Policy. The vulnerability, located in the testcase_read function, could lead to a denial of service. With a CVSS score of 3.3, it requires local access and user interaction for exploitation, but has a low impact on availability. There is no evidence of active exploitation, publicly available exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage, indicating a low current threat level.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.7.17CPE matchmatch criteria | cpe:2.3:a:opensuse:libsolv:*:*:*:*:*:*:*:* | ||
1.15.0CPE matchmatch criteria | cpe:2.3:a:oracle:communications_cloud_native_core_policy:1.15.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Buffer overflow vulnerability in libsolv 2020-12-13 via the Solver * testcase_read(Pool *pool FILE *fp const char *testcase Queue *job char **resultp int *resultflagsp function at src/testcase.c: line 2334 which could cause a denial of service
May 11, 2021libsolv: heap-based buffer overflow in testcase_read() in src/testcase.c
Dec 13, 2020