Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2019-17362
Description:In LibTomCrypt through 1.18.2, the der_decode_utf8_string function (in der_decode_utf8_string.c) does not properly detect certain invalid UTF-8 sequences. This allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) or read information from other memory locations via carefully crafted DER-encoded data.
Test IDs: 1.3.6.1.4.1.25623.1.1.10.2020.0028   1.3.6.1.4.1.25623.1.1.2.2021.2181   1.3.6.1.4.1.25623.1.1.2.2022.1079   1.3.6.1.4.1.25623.1.0.885446   1.3.6.1.4.1.25623.1.1.2.2021.2273   1.3.6.1.4.1.25623.1.0.852766   1.3.6.1.4.1.25623.1.0.885445   1.3.6.1.4.1.25623.1.1.12.2021.4868.1   1.3.6.1.4.1.25623.1.0.852861   1.3.6.1.4.1.25623.1.1.2.2021.2247   1.3.6.1.4.1.25623.1.1.2.2021.2196   1.3.6.1.4.1.25623.1.0.891951   1.3.6.1.4.1.25623.1.1.2.2021.2303  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2019-17362
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YU5OMCY3PX54YVI4FMNDEENHDJZJ3RJW/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/47YP5SXQ4RY6KMTK2HI5ZZR244XKRMCZ/
https://github.com/libtom/libtomcrypt/issues/507
https://github.com/libtom/libtomcrypt/pull/508
https://vuldb.com/?id.142995
https://lists.debian.org/debian-lts-announce/2019/10/msg00010.html
SuSE Security Announcement: openSUSE-SU-2019:2454 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00020.html
SuSE Security Announcement: openSUSE-SU-2019:2514 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00041.html




© 1998-2025 E-Soft Inc. All rights reserved.