Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2019:2454-1

Опубликовано: 09 нояб. 2019
Источник: suse-cvrf

Описание

Security update for libtomcrypt

This update for libtomcrypt fixes the following issue:

CVE-2019-17362: Fixed an improper detection of invalid UTF-8 sequences that could have led to DoS or information disclosure via crafted DER-encoded data (bsc#1153433).

This update was imported from the SUSE:SLE-15:Update update project.

Список пакетов

openSUSE Leap 15.0
libtomcrypt-devel-1.17-lp150.2.3.1
libtomcrypt-examples-1.17-lp150.2.3.1
libtomcrypt0-1.17-lp150.2.3.1

Описание

In LibTomCrypt through 1.18.2, the der_decode_utf8_string function (in der_decode_utf8_string.c) does not properly detect certain invalid UTF-8 sequences. This allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) or read information from other memory locations via carefully crafted DER-encoded data.


Затронутые продукты
openSUSE Leap 15.0:libtomcrypt-devel-1.17-lp150.2.3.1
openSUSE Leap 15.0:libtomcrypt-examples-1.17-lp150.2.3.1
openSUSE Leap 15.0:libtomcrypt0-1.17-lp150.2.3.1

Ссылки