CVE-2019-5039
Description
An exploitable command execution vulnerability exists in the ASN1 certificate writing functionality of Openweave-core version 4.0.2. A specially crafted weave certificate can trigger a heap-based buffer overflow, resulting in code execution. An attacker can craft a weave certificate to trigger this vulnerability.
CWE
- CWE-122 — CWE-122: Heap-based Buffer Overflow
Affected
- n/a / Nest Labs — v=Nest Labs Openweave-core 4.0.2 [affected]
CVSS
- 3.0 score=7.5 severity=HIGH
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
References
- https://talosintelligence.com/vulnerability_reports/TALOS-2019-0802 x_refsource_MISC
Source
cvelistV5-main/cves/2019/5xxx/CVE-2019-5039.json