CVE-2019-25048: High severity libressl vulnerability
LibreSSL 2.9.1 through 3.2.1 has a heap-based buffer over-read in doprintex (called from asn1itemprintctx and ASN1itemprint).
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2019-25048?
CVE-2019-25048 is a vulnerability in LibreSSL versions 2.9.1 through 3.2.1 that allows for a heap-based buffer over-read.
How does CVE-2019-25048 affect OpenBSD LibreSSL?
CVE-2019-25048 affects OpenBSD LibreSSL versions 2.9.1 through 3.2.1.
What is the severity of CVE-2019-25048?
CVE-2019-25048 has a severity rating of 7.1 (high).
How can I fix CVE-2019-25048?
To fix CVE-2019-25048, update to a version of LibreSSL that is later than 3.2.1.
Where can I find more information about CVE-2019-25048?
More information about CVE-2019-25048 can be found at the following references: [Reference 1](https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=13914), [Reference 2](https://github.com/google/oss-fuzz-vulns/blob/main/vulns/libressl/OSV-2020-1923.yaml), [Reference 3](https://github.com/libressl-portable/portable/commit/17c88164016df821df2dff4b2b1291291ec4f28a).