CVE-2021-33930: Buffer Overflow
Buffer overflow vulnerability in function poolinstallablewhatprovides in src/repo.h in libsolv before 0.7.17 allows attackers to cause a Denial of Service.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-33930?
CVE-2021-33930 is a vulnerability in Libsolv that can be exploited by a remote attacker to cause a denial of service.
What is the severity of CVE-2021-33930?
The severity of CVE-2021-33930 is medium, with a severity value of 5.3.
Which software is affected by CVE-2021-33930?
Libsolv version up to exclusive 0.7.17, IBM QRadar SIEM versions 7.5.0 GA, 7.4.3 GA - 7.4.3 FP4, and 7.3.3 GA - 7.3.3 FP10 are affected by CVE-2021-33930.
How can I fix CVE-2021-33930?
To fix CVE-2021-33930, update Libsolv to version 0.7.17 or apply the respective patches for the affected IBM QRadar SIEM versions.
Where can I find more information about CVE-2021-33930?
More information about CVE-2021-33930 can be found in the references provided: [GitHub Issue](https://github.com/openSUSE/libsolv/issues/417), [Red Hat Bugzilla](https://bugzilla.redhat.com/show_bug.cgi?id=2000706), [GitHub Commit](https://github.com/openSUSE/libsolv/commit/0077ef29eb46d2e1df2f230fc95a1d9748d49dec).