PYSEC-2019-100

See a problem?
Import Source
https://github.com/pypa/advisory-database/blob/main/vulns/libyang/PYSEC-2019-100.yaml
JSON Data
https://api.osv.dev/v1/vulns/PYSEC-2019-100
Withdrawn
2023-03-14T07:01:09.337952Z
Published
2019-12-06T16:15:00Z
Modified
2023-03-14T07:01:09.337952Z
Summary
[none]
Details

In all versions of libyang before 1.0-r5, a stack-based buffer overflow was discovered in the way libyang parses YANG files with a leaf of type "bits". An application that uses libyang to parse untrusted YANG files may be vulnerable to this flaw, which would allow an attacker to cause a denial of service or possibly gain code execution.

References

Affected packages