Vulnerability CVE-2019-6135: Information

Description

An issue has been found in libIEC61850 v1.3.1. Memory_malloc in hal/memory/lib_memory.c has a memory leak when called from Asn1PrimitiveValue_create in mms/asn1/asn1_ber_primitive_value.c, as demonstrated by goose_publisher_example.c and iec61850_9_2_LE_example.c.

Severity: HIGH (7.5) Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Published: Jan. 11, 2019
Modified: Aug. 24, 2020
Error type identifier: CWE-401

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
libiec61850sisyphus1.4.2.1-alt11.5.0-alt1ALT-PU-2020-3467-1263085Fixed
libiec61850p101.4.2.1-alt11.4.2.1-alt1ALT-PU-2020-3467-1263085Fixed
libiec61850p91.4.2.1-alt11.4.2.1-alt1ALT-PU-2020-3487-1263099Fixed
libiec61850c10f11.4.2.1-alt11.4.2.1-alt1ALT-PU-2020-3467-1263085Fixed

References to Advisories, Solutions, and Tools

    1. Configuration 1

      cpe:2.3:a:mz-automation:libiec61850:1.3.1:*:*:*:*:*:*:*