CVE-2019-25052: Critical severity Linaro OP-TEE vulnerability
Published Aug 11, 2021
·Updated
In Linaro OP-TEE before 3.7.0, by using inconsistent or malformed data, it is possible to call update and final cryptographic functions directly, causing a crash that could leak sensitive information.
Affected Software
2 affected components
Linaro OP-TEE<3.7.0
TrustedFirmware OP-TEE<3.7.0
Remediation
Event History
Aug 11, 2021
CVE Published
via MITRE·02:59 PM
Data Sourced
via MITRE·02:59 PM
Description
Data Sourced
via NVD·03:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2019-25052?
The severity of CVE-2019-25052 is critical with a CVSS score of 9.1.
2
How can an attacker exploit CVE-2019-25052?
An attacker can exploit CVE-2019-25052 by using inconsistent or malformed data to call update and final cryptographic functions directly, causing a crash and potentially leaking sensitive information.
3
Which software versions are affected by CVE-2019-25052?
Linaro OP-TEE versions up to exclusive 3.7.0 are affected by CVE-2019-25052.
4
How can I fix CVE-2019-25052?
To fix CVE-2019-25052, update Linaro OP-TEE to version 3.7.0 or later.
5
What is the Common Weakness Enumeration (CWE) ID for CVE-2019-25052?
The Common Weakness Enumeration (CWE) ID for CVE-2019-25052 is CWE-327.