PT-2019-16020 · Unknown · Libiec61850
Sleicasper
·
Published
2019-12-24
·
Updated
2020-08-24
·
CVE-2019-19958
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
libIEC61850 version 1.4.0
Description
The issue is related to an integer signedness problem in the StringUtils createStringFromBuffer function, located in common/string utilities.c. This could potentially lead to an attempted excessive memory allocation, resulting in a denial of service.
Recommendations
For libIEC61850 version 1.4.0, consider applying a patch or fix that addresses the integer signedness issue in the StringUtils createStringFromBuffer function to prevent potential denial of service attacks.
Exploit
Fix
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Libiec61850