CVE-2019-17362: Critical severity libmcrypt vulnerability
In LibTomCrypt through 1.18.2, the derdecodeutf8string function (in derdecodeutf8string.c) does not properly detect certain invalid UTF-8 sequences. This allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) or read information from other memory locations via carefully crafted DER-encoded data.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2019-17362?
CVE-2019-17362 is a vulnerability in LibTomCrypt through 1.18.2 that allows context-dependent attackers to cause a denial of service or read information from other memory locations.
How does CVE-2019-17362 impact LibTomCrypt?
CVE-2019-17362 can lead to an out-of-bounds read and crash, or allow attackers to read information from other memory locations in LibTomCrypt.
What is the severity of CVE-2019-17362?
The severity of CVE-2019-17362 is critical with a CVSS score of 9.1.
How can context-dependent attackers exploit CVE-2019-17362?
Context-dependent attackers can exploit CVE-2019-17362 to cause a denial of service or read information from other memory locations in LibTomCrypt.
Are there any patches or fixes available for CVE-2019-17362?
At the time of this writing, patches or fixes for CVE-2019-17362 may be available from the official LibTomCrypt website or the relevant software vendor.