Описание
Security update for libtomcrypt
This update for libtomcrypt fixes the following issue:
CVE-2019-17362: Fixed an improper detection of invalid UTF-8 sequences that could have led to DoS or information disclosure via crafted DER-encoded data (bsc#1153433).
This update was imported from the SUSE:SLE-15:Update update project.
Список пакетов
openSUSE Leap 15.0
libtomcrypt-devel-1.17-lp150.2.3.1
libtomcrypt-examples-1.17-lp150.2.3.1
libtomcrypt0-1.17-lp150.2.3.1
Ссылки
- E-Mail link for openSUSE-SU-2019:2454-1
- SUSE Security Ratings
- SUSE Bug 1153433
- SUSE CVE CVE-2019-17362 page
Описание
In LibTomCrypt through 1.18.2, the der_decode_utf8_string function (in der_decode_utf8_string.c) does not properly detect certain invalid UTF-8 sequences. This allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) or read information from other memory locations via carefully crafted DER-encoded data.
Затронутые продукты
openSUSE Leap 15.0:libtomcrypt-devel-1.17-lp150.2.3.1
openSUSE Leap 15.0:libtomcrypt-examples-1.17-lp150.2.3.1
openSUSE Leap 15.0:libtomcrypt0-1.17-lp150.2.3.1
Ссылки
- CVE-2019-17362
- SUSE Bug 1153433