CVE-2020-14150

NameCVE-2020-14150
DescriptionGNU Bison before 3.5.4 allows attackers to cause a denial of service (application crash).
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
NVD severitylow

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
bison (PTS)stretch2:3.0.4.dfsg-1vulnerable
buster2:3.3.2.dfsg-1vulnerable
bullseye, sid2:3.6.3+dfsg-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
bisonsource(unstable)2:3.6.1+dfsg-1unimportant

Notes

https://lists.gnu.org/archive/html/info-gnu/2020-04/msg00000.html
Crash in CLI tool, no security impact

Search for package or bug name: Reporting problems