libtomcrypt: out-of-bounds read in the der_decode_utf8_string function in der_decode_utf8_string.c
Published Oct 9, 2019
9.1
CRITICALCVSS 3.1
EPSS 3.11%
Description
In LibTomCrypt through 1.18.2, the der_decode_utf8_string function (in der_decode_utf8_string.c) does not properly detect certain invalid UTF-8 sequences. This allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) or read information from other memory locations via carefully crafted DER-encoded data.
Affected products
No data.
Configuration 1
- ≤ 1.18.2
Configuration 2
- 8.0
No data.
CloudForms Management Engine 5
libtomcrypt
Not affected
Red Hat Ansible Engine 2
libtomcrypt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| CloudForms Management Engine 5 | libtomcrypt | Not affected | n/a |
| Red Hat Ansible Engine 2 | libtomcrypt | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat CloudForms 5.9, 5.10 and 5.11 are not affected as it does not ship anymore libtomcrypt library. Only CloudForms 5.8 which is EOL delivers libtomcrypt library. Red Hat Ansible Engine 2.8 and 2.9 are not affected as it does not ship libtomcrypt library anymore and Ansible Engine 2.7 had deprecate it.
References (14)
- http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00020.html vendor-advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00041.html vendor-advisory
- https://access.redhat.com/security/cve/CVE-2019-17362 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1775212 Issue Tracking
- https://github.com/libtom/libtomcrypt/issues/507 ExploitThird Party Advisory
- https://github.com/libtom/libtomcrypt/pull/508 PatchThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/10/msg00010.html mailing-listMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/47YP5SXQ4RY6KMTK2HI5ZZR244XKRMCZ/ vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YU5OMCY3PX54YVI4FMNDEENHDJZJ3RJW/ vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/47YP5SXQ4RY6KMTK2HI5ZZR244XKRMCZ/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YU5OMCY3PX54YVI4FMNDEENHDJZJ3RJW/
- https://nvd.nist.gov/vuln/detail/CVE-2019-17362
- https://vuldb.com/?id.142995 Permissions Required
- https://www.cve.org/CVERecord?id=CVE-2019-17362
Change history (0)
No recorded changes yet.