CVE-2019-3817: Rpm Libcomps
High severity, CVSS 8.8. EPSS: 1.7% chance of exploitation in the next 30 days.
A use-after-free flaw has been discovered in libcomps before version 0.1.10 in the way ObjMRTrees are merged. An attacker, who is able to make an application read a crafted comps XML file, may be able to crash the application or execute malicious code.
Affected products
- Rpm Libcomps: before 0.1.10 (fixed in 0.1.10)
Published 2019-03-27. Last modified 2026-06-17.