Integer Signedness Error in libIEC61850 Affects MmsValue_newOctetString
CVE-2019-19930

6.5MEDIUM

Key Information:

Vendor
CVE Published:
23 December 2019

What is CVE-2019-19930?

In the libIEC61850 library version 1.4.0, an integer signedness error exists within the MmsValue_newOctetString function, located in mms/iso_mms/common/mms_value.c. This vulnerability could potentially result in excessive memory allocation attempts, which may affect application stability and security. It is crucial for users and developers to review and mitigate this issue to ensure proper functioning and security of their implementations.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.