EPSS
Percentile
67.9%
libyang.so is vulnerable to denial of service (DoS). The library do not restrict the input of unprintable characters at the end of the file, causing SIGSEGV signals in yanglint and yangfuzz and crashing the application.
yanglint
yangfuzz
bugzilla.redhat.com/show_bug.cgi?id=1793935
github.com/CESNET/libyang/commit/7852b272ef77f8098c35deea6c6f09cb78176f08
github.com/CESNET/libyang/compare/v1.0-r2...v1.0-r3
github.com/CESNET/libyang/issues/773