CVE-2019-19962: High severity wolfssl wolfmqtt vulnerability
Published Dec 24, 2019
·Updated
wolfSSL before 4.3.0 mishandles calls to wcSignatureGenerateHash, leading to fault injection in RSA cryptography.
Affected Software
1 affected component
wolfSSL wolfssl<4.3.0
Remediation
Event History
Dec 24, 2019
CVE Published
via MITRE·11:03 PM
Data Sourced
via MITRE·11:03 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2019-19962.
2
What is the severity of CVE-2019-19962?
The severity of CVE-2019-19962 is high (7.5).
3
What is the affected software?
The affected software is wolfSSL versions up to, but excluding, 4.3.0.
4
What is the description of this vulnerability?
This vulnerability in wolfSSL versions before 4.3.0 mishandles calls to wc_SignatureGenerateHash, leading to fault injection in RSA cryptography.
5
How do I fix CVE-2019-19962?
To fix CVE-2019-19962, update wolfSSL to version 4.3.0 or later.