Integer Signedness Issue in libIEC61850 by MZ Automation
CVE-2019-19958
6.5MEDIUM
What is CVE-2019-19958?
In libIEC61850 version 1.4.0, a flaw has been identified in the StringUtils_createStringFromBuffer function located in common/string_utilities.c. This vulnerability stems from an integer signedness issue that can potentially result in an excessive memory allocation attempt, which may lead to a denial of service. Adequate precautions should be taken to mitigate the risks associated with this vulnerability.
