CVE-2019-16510: Use After Free
Published Sep 19, 2019
·Updated
libIEC61850 through 1.3.3 has a use-after-free in MmsServerwaitReady in mms/isomms/server/mmsserver.c, as demonstrated by serverexamplegoose.
Affected Software
1 affected component
mz-automation libiec61850<=1.3.3
Event History
Sep 19, 2019
CVE Published
via MITRE·03:39 PM
Data Sourced
via MITRE·03:39 PM
Description
Frequently Asked Questions
1
What is CVE-2019-16510?
CVE-2019-16510 is a vulnerability in libIEC61850, specifically in the MmsServer_waitReady function in mms_server.c.
2
How severe is CVE-2019-16510?
The severity of CVE-2019-16510 is high with a CVSS score of 7.5.
3
What is the affected software for CVE-2019-16510?
The affected software is libIEC61850 version up to and including 1.3.3.
4
What is the CWE for CVE-2019-16510?
The CWE for CVE-2019-16510 is CWE-416.
5
How can I fix CVE-2019-16510?
To fix CVE-2019-16510, upgrade to a version of libIEC61850 higher than 1.3.3.