CVE-2019-19930: Integer Overflow
Published Dec 23, 2019
·Updated
In libIEC61850 1.4.0, MmsValuenewOctetString in mms/isomms/common/mmsvalue.c has an integer signedness error that can lead to an attempted excessive memory allocation.
Affected Software
1 affected component
mz-automation libiec61850=1.4.0
Event History
Dec 23, 2019
CVE Published
via MITRE·02:02 AM
Data Sourced
via MITRE·02:02 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-19930?
CVE-2019-19930 is classified as a moderate severity vulnerability due to the potential for excessive memory allocation.
2
How do I fix CVE-2019-19930?
To fix CVE-2019-19930, upgrade to a version of libIEC61850 that addresses this integer signedness error.
3
Which versions of libIEC61850 are affected by CVE-2019-19930?
CVE-2019-19930 specifically affects version 1.4.0 of libIEC61850.
4
What can be exploited due to CVE-2019-19930?
CVE-2019-19930 can be exploited to cause an application to attempt excessive memory allocation, leading to potential denial of service.
5
Is CVE-2019-19930 also known by another name?
CVE-2019-19930 does not have any known aliases and is referenced solely by this ID.