CVE-2019-25049: High severity libressl vulnerability
Published Jul 1, 2021
·Updated
LibreSSL 2.9.1 through 3.2.1 has an out-of-bounds read in asn1itemprintctx (called from asn1templateprintctx).
Affected Software
2 affected components
OpenBSD LibreSSL>=2.9.1<=3.2.1
Linux Linux kernel
Remediation
Patch Available
Event History
Jul 1, 2021
CVE Published
via MITRE·02:53 AM
Data Sourced
via MITRE·02:53 AM
Description
Frequently Asked Questions
1
What is CVE-2019-25049?
CVE-2019-25049 is a vulnerability found in LibreSSL versions 2.9.1 through 3.2.1 that allows for an out-of-bounds read in the asn1_item_print_ctx function.
2
How does CVE-2019-25049 affect OpenBSD Libressl?
CVE-2019-25049 affects OpenBSD Libressl versions 2.9.1 through 3.2.1.
3
What is the severity of CVE-2019-25049?
CVE-2019-25049 has a severity rating of 7.1 (high).
4
How can I fix CVE-2019-25049?
To fix CVE-2019-25049, update to a version of LibreSSL that is not affected by the vulnerability (version 3.2.2 or higher).
5
Where can I find more information about CVE-2019-25049?
You can find more information about CVE-2019-25049 on the following references: [link1], [link2], [link3].