A segmentation fault in CVC5 Solver v1.1.3 allows attackers to cause a Denial of Service (DoS) via a crafted SMT-LIB input file containing the set-logic command with specific formatting errors.
{
"priority_reason": "CLI crash only.",
"binaries": [
{
"binary_version": "1.1.2-1build1",
"binary_name": "cvc5"
},
{
"binary_version": "1.1.2-1build1",
"binary_name": "libcvc5-1"
},
{
"binary_version": "1.1.2-1build1",
"binary_name": "libcvc5-dev"
},
{
"binary_version": "1.1.2-1build1",
"binary_name": "libcvc5parser1"
},
{
"binary_version": "1.1.2-1build1",
"binary_name": "python3-cvc5"
}
]
}
{
"priority_reason": "CLI crash only.",
"binaries": [
{
"binary_version": "1.1.2-2build1",
"binary_name": "cvc5"
},
{
"binary_version": "1.1.2-2build1",
"binary_name": "libcvc5-1"
},
{
"binary_version": "1.1.2-2build1",
"binary_name": "libcvc5-dev"
},
{
"binary_version": "1.1.2-2build1",
"binary_name": "libcvc5parser1"
},
{
"binary_version": "1.1.2-2build1",
"binary_name": "python3-cvc5"
}
]
}
{
"priority_reason": "CLI crash only.",
"binaries": [
{
"binary_version": "1.1.2-2build1",
"binary_name": "cvc5"
},
{
"binary_version": "1.1.2-2build1",
"binary_name": "libcvc5-1"
},
{
"binary_version": "1.1.2-2build1",
"binary_name": "libcvc5-dev"
},
{
"binary_version": "1.1.2-2build1",
"binary_name": "libcvc5parser1"
},
{
"binary_version": "1.1.2-2build1",
"binary_name": "python3-cvc5"
}
]
}