{"id":"CVE-2019-17362","details":"In LibTomCrypt through 1.18.2, the der_decode_utf8_string function (in der_decode_utf8_string.c) does not properly detect certain invalid UTF-8 sequences. This allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) or read information from other memory locations via carefully crafted DER-encoded data.","modified":"2026-07-08T05:54:56.978982674Z","published":"2019-10-09T01:15:10.130Z","related":["SUSE-SU-2019:2808-1","SUSE-SU-2019:3095-1","openSUSE-SU-2019:2454-1","openSUSE-SU-2019:2514-1"],"database_specific":{"unresolved_ranges":[{"extracted_events":[{"introduced":"8.0"},{"last_affected":"8.0"}],"cpes":["cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*"],"vendor_product":"debian:debian_linux","source":"CPE_STRING"}]},"references":[{"type":"WEB","url":"http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00020.html"},{"type":"WEB","url":"http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00041.html"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/47YP5SXQ4RY6KMTK2HI5ZZR244XKRMCZ/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YU5OMCY3PX54YVI4FMNDEENHDJZJ3RJW/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/47YP5SXQ4RY6KMTK2HI5ZZR244XKRMCZ/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YU5OMCY3PX54YVI4FMNDEENHDJZJ3RJW/"},{"type":"ADVISORY","url":"https://lists.debian.org/debian-lts-announce/2019/10/msg00010.html"},{"type":"REPORT","url":"https://vuldb.com/?id.142995"},{"type":"FIX","url":"https://github.com/libtom/libtomcrypt/pull/508"},{"type":"EVIDENCE","url":"https://github.com/libtom/libtomcrypt/issues/507"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/libtom/libtomcrypt","events":[{"introduced":"0"},{"last_affected":"7e7eb695d581782f04b24dc444cbfde86af59853"}],"database_specific":{"cpe":"cpe:2.3:a:libtom:libtomcrypt:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"1.18.2"}],"source":"CPE_RANGE"}}],"versions":["v1.18.2","v1.18.1","v1.18.0","1.17","1.16","1.15","1.14","1.13","1.12","1.11","1.10","1.09","1.08","1.07","1.06","1.05","1.04","1.03","1.02","1.01","1.00","0.99","0.98","0.97b","0.97a","0.97","0.96","0.95","0.94","0.93","0.92","0.91","0.90","0.89","0.88","0.87","0.86","0.85","0.84","0.83","0.82","0.81","0.80","0.79","0.78","0.77","0.76","0.75"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-17362.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"}]}