CVE-2019-19958: Medium severity mz automation libiec61850 vulnerability
Published Dec 24, 2019
·Updated
In libIEC61850 1.4.0, StringUtilscreateStringFromBuffer in common/stringutilities.c has an integer signedness issue that could lead to an attempted excessive memory allocation and denial of service.
Affected Software
1 affected component
mz-automation libiec61850=1.4.0
Event History
Dec 24, 2019
CVE Published
via MITRE·09:58 PM
Data Sourced
via MITRE·09:58 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-19958?
CVE-2019-19958 is classified with a moderate severity level due to its potential for causing denial of service.
2
How do I fix CVE-2019-19958?
To fix CVE-2019-19958, update to a later, patched version of libIEC61850, as version 1.4.0 is vulnerable.
3
What software is affected by CVE-2019-19958?
CVE-2019-19958 affects libIEC61850 version 1.4.0 developed by MZ Automation.
4
What type of vulnerability is CVE-2019-19958?
CVE-2019-19958 is an integer signedness issue that can result in excessive memory allocation.
5
Can CVE-2019-19958 lead to data loss?
While CVE-2019-19958 primarily leads to denial of service, it does not directly cause data loss.