CVE-2019-11638 (NVD)

2019-05-01

An issue was discovered in GNU recutils 1.8. There is a NULL pointer dereference in the function rec_field_name_equal_p at rec-field-name.c in librec.a, leading to a crash.

Products Recutils
Type Out-of-bounds Read (CWE-125)
NULL Pointer Dereference (CWE-476)
First patch - None (likely due to unavailable code)
Links https://github.com/TeamSeri0us/pocs/tree/master/recutils/bug-report-recutils/rec2csv
https://github.com/TeamSeri0us/pocs/blob/master/recutils/bug-report-recutils