CVE-2021-44577
Publication date 21 February 2022
Last updated 4 August 2025
Ubuntu priority
Cvss 3 Severity Score
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-3200 Reason: This candidate is a duplicate of CVE-2021-3200. Notes: All CVE users should reference CVE-2021-3200 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage
Status
Package | Ubuntu Release | Status |
---|---|---|
libsolv | 22.04 LTS jammy |
Not affected
|
20.04 LTS focal |
Not affected
|
|
18.04 LTS bionic |
Not affected
|
|
16.04 LTS xenial |
Not affected
|
|
14.04 LTS trusty | Ignored end of standard support |
Severity score breakdown
Parameter | Value |
---|---|
Base score |
|
Attack vector | Network |
Attack complexity | Low |
Privileges required | None |
User interaction | Required |
Scope | Unchanged |
Confidentiality | None |
Integrity impact | None |
Availability impact | High |
Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H |
References
Other references
- https://github.com/openSUSE/libsolv/issues/428
- https://github.com/openSUSE/libsolv/commit/0077ef29eb46d2e1df2f230fc95a1d9748d49dec (0.7.17)
- https://github.com/yangjiageng/PoC/blob/master/libsolv-PoCs/propagate-524
- https://github.com/yangjiageng/PoC/blob/master/libsolv-PoCs/propagate-490
- https://www.cve.org/CVERecord?id=CVE-2021-44577