CVE-2018-19185

Severity CVSS v4.0:
Pending analysis
Type:
CWE-787 Out-of-bounds Write
Publication date:
12/11/2018
Last modified:
24/08/2020

Description

An issue has been found in libIEC61850 v1.3. It is a heap-based buffer overflow in BerEncoder_encodeOctetString in mms/asn1/ber_encoder.c. This is exploitable even after CVE-2018-18834 has been patched, with a different dataSetValue sequence than the CVE-2018-18834 attack vector.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mz-automation:libiec61850:1.3:*:*:*:*:*:*:*