First published: Wed Aug 11 2021(Updated: )
In Linaro OP-TEE before 3.7.0, by using inconsistent or malformed data, it is possible to call update and final cryptographic functions directly, causing a crash that could leak sensitive information.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Linaro OP-TEE | <3.7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-25052 is critical with a CVSS score of 9.1.
An attacker can exploit CVE-2019-25052 by using inconsistent or malformed data to call update and final cryptographic functions directly, causing a crash and potentially leaking sensitive information.
Linaro OP-TEE versions up to exclusive 3.7.0 are affected by CVE-2019-25052.
To fix CVE-2019-25052, update Linaro OP-TEE to version 3.7.0 or later.
The Common Weakness Enumeration (CWE) ID for CVE-2019-25052 is CWE-327.