CVE-2019-16748: Critical severity wolfssl wolfmqtt vulnerability
Published Sep 24, 2019
·Updated
In wolfSSL through 4.1.0, there is a missing sanity check of memory accesses in parsing ASN.1 certificate data while handshaking. Specifically, there is a one-byte heap-based buffer over-read in CheckCertSignatureex in wolfcrypt/src/asn.c.
Affected Software
1 affected component
wolfSSL wolfssl<=4.1.0
Event History
Sep 24, 2019
CVE Published
via MITRE·12:12 PM
Data Sourced
via MITRE·12:12 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2019-16748.
2
What is the severity of CVE-2019-16748?
The severity of CVE-2019-16748 is critical with a CVSS score of 9.8.
3
What is the affected software?
The affected software is Wolfssl version up to and including 4.1.0.
4
Which component of Wolfssl is affected by CVE-2019-16748?
The component affected by CVE-2019-16748 is CheckCertSignature_ex in wolfcrypt/src/asn.c.
5
Is there a fix available for CVE-2019-16748?
Yes, the fix for CVE-2019-16748 is available. It is recommended to update to a version of Wolfssl that is higher than 4.1.0.