CVE-2018-19185: Buffer Overflow
An issue has been found in libIEC61850 v1.3. It is a heap-based buffer overflow in BerEncoderencodeOctetString in mms/asn1/berencoder.c. This is exploitable even after CVE-2018-18834 has been patched, with a different dataSetValue sequence than the CVE-2018-18834 attack vector.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-19185?
CVE-2018-19185 is classified as a critical vulnerability due to the potential for remote code execution through heap-based buffer overflow.
How do I fix CVE-2018-19185?
To fix CVE-2018-19185, upgrade to a patched version of libIEC61850 that addresses this buffer overflow issue.
What are the effects of exploiting CVE-2018-19185?
Exploiting CVE-2018-19185 can lead to arbitrary code execution in the context of the affected application.
Which software versions are affected by CVE-2018-19185?
CVE-2018-19185 specifically affects version 1.3 of the libIEC61850 library.
Is CVE-2018-19185 related to CVE-2018-18834?
Yes, CVE-2018-19185 is a separate vulnerability that remains exploitable even after the fix for CVE-2018-18834 has been applied.