First published: Wed Oct 09 2019(Updated: )
In LibTomCrypt through 1.18.2, the der_decode_utf8_string function (in der_decode_utf8_string.c) does not properly detect certain invalid UTF-8 sequences. This allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) or read information from other memory locations via carefully crafted DER-encoded data.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Libtom Libtomcrypt | <=1.18.2 | |
Debian Debian Linux | =8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-17362 is a vulnerability in LibTomCrypt through 1.18.2 that allows context-dependent attackers to cause a denial of service or read information from other memory locations.
CVE-2019-17362 can lead to an out-of-bounds read and crash, or allow attackers to read information from other memory locations in LibTomCrypt.
The severity of CVE-2019-17362 is critical with a CVSS score of 9.1.
Context-dependent attackers can exploit CVE-2019-17362 to cause a denial of service or read information from other memory locations in LibTomCrypt.
At the time of this writing, patches or fixes for CVE-2019-17362 may be available from the official LibTomCrypt website or the relevant software vendor.