Out-of-bounds read In libtomcrypt
Description
In LibTomCrypt through 1.18.2, the der_decode_utf8_string function (in der_decode_utf8_string.c) does not properly detect certain invalid UTF-8 sequences. This allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) or read information from other memory locations via carefully crafted DER-encoded data.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
debian 14 | 1.18.2-3 | ||
alpine v3.20 | 0.079-r0 | ||
alpine v3.22 | 0.079-r0 | ||
debian 11 | 1.18.2-3 | ||
debian 12 | 1.18.2-3 | ||
debian 13 | 1.18.2-3 | ||
alpine v3.21 | 0.079-r0 | ||
alpine v3.19 | 0.079-r0 | ||
alpine v3.23 | 0.079-r0 |
Aliases
1. 2. 3. 4. 5. 6. 7.