Out-of-bounds read in libtomcrypt - CVE-2019-17362
Published: November 10, 2019
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) atttack.
The vulnerability exists due to a boundary condition within the der_decode_utf8_string() function in der_decode_utf8_string.c file in LibTomCrypt. A remote attacker can pass to the application specially crafted DER-encoded data, trigger out-of-bounds read error and cause application crash.
Affected software
Opensuse
openEuler
Fedora
perl-CryptX
libtomcrypt
libtomcrypt-debuginfo
libtomcrypt-debugsource
libtomcrypt-devel
How to mitigate CVE-2019-17362
libtomcrypt - update to 1.18.2-4
libtomcrypt-debuginfo - update to 1.18.2-4
libtomcrypt-debugsource - update to 1.18.2-4
libtomcrypt-devel - update to 1.18.2-4