Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-17362

Опубликовано: 10 авг. 2019
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

In LibTomCrypt through 1.18.2, the der_decode_utf8_string function (in der_decode_utf8_string.c) does not properly detect certain invalid UTF-8 sequences. This allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) or read information from other memory locations via carefully crafted DER-encoded data.

Отчет

Red Hat CloudForms 5.9, 5.10 and 5.11 are not affected as it does not ship anymore libtomcrypt library. Only CloudForms 5.8 which is EOL delivers libtomcrypt library. Red Hat Ansible Engine 2.8 and 2.9 are not affected as it does not ship libtomcrypt library anymore and Ansible Engine 2.7 had deprecate it.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
CloudForms Management Engine 5libtomcryptNot affected
Red Hat Ansible Engine 2libtomcryptNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=1775212libtomcrypt: out-of-bounds read in the der_decode_utf8_string function in der_decode_utf8_string.c

EPSS

Процентиль: 64%
0.00473
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 9.1
ubuntu
больше 6 лет назад

In LibTomCrypt through 1.18.2, the der_decode_utf8_string function (in der_decode_utf8_string.c) does not properly detect certain invalid UTF-8 sequences. This allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) or read information from other memory locations via carefully crafted DER-encoded data.

CVSS3: 9.1
nvd
больше 6 лет назад

In LibTomCrypt through 1.18.2, the der_decode_utf8_string function (in der_decode_utf8_string.c) does not properly detect certain invalid UTF-8 sequences. This allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) or read information from other memory locations via carefully crafted DER-encoded data.

CVSS3: 9.1
msrc
около 4 лет назад

Описание отсутствует

CVSS3: 9.1
debian
больше 6 лет назад

In LibTomCrypt through 1.18.2, the der_decode_utf8_string function (in ...

suse-cvrf
около 6 лет назад

Security update for libtomcrypt

EPSS

Процентиль: 64%
0.00473
Низкий

6.5 Medium

CVSS3