In LibTomCrypt through 1.18.2, the der_decode_utf8_string function (in der_decode_utf8_string.c) does not properly detect certain invalid UTF-8 sequences. This allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) or read information from other memory locations via carefully crafted DER-encoded data.
CVSS Details
- CVSS 3.1 Base Score: 9.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade perl-cryptx | Mar 26, 2024 | Oct 9, 2019 |
| Debian | — | Upgrade libtomcrypt | Oct 11, 2019 | Oct 9, 2019 |
| Huawei Euleros 2_0_sp8 | — | Upgrade libtomcrypt | Aug 10, 2021 | Oct 9, 2019 |
| Huawei Euleros 2_0_sp9 | — | Upgrade libtomcrypt | Aug 10, 2021 | Oct 9, 2019 |
| Suse | — | Upgrade libtomcrypt-examplesUpgrade libtomcrypt-develUpgrade libtomcrypt0 | Nov 12, 2019 | Oct 9, 2019 |
| Ubuntu | — | Upgrade libtomcrypt1 (Ubuntu Pro)Upgrade libtomcrypt0 (Ubuntu Pro) | Mar 22, 2023 | Oct 9, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub