Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2019-17362

29
FAUCET Score

CVE-2019-17362 is a critical vulnerability in LibTomCrypt versions up to 1.18.2, affecting Debian Linux and LibTomCrypt itself. It stems from improper UTF-8 sequence detection in the der_decode_utf8_string function, allowing attackers to trigger an out-of-bounds read, leading to a denial of service or information disclosure. With a CVSS score of 9.1 (CRITICAL), this vulnerability is remotely exploitable with low attack complexity and no user interaction required, posing a high risk to confidentiality and availability. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage, suggesting it is not widely known or exploited in the wild.

Impacted Technologies

VendorProductVersion(s)CPE
<= 1.18.2CPE matchmatch criteria
cpe:2.3:a:libtom:libtomcrypt:*:*:*:*:*:*:*:*
8.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

9.1CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.2
CvssVersion
3.1

Exploit Intelligence

EPSS Score
3.11%
Probability of exploitation in next 30 days
EPSS Percentile
86.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-24
Model: v2026.06.15
This CVE's current EPSS score of 0.0311 is in the 78th percentile among its peer group of 36,821 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (10)

github_advisorypatch availablevia nvd_reference
View patch
microsoftpatch availablevia msrc
Product: 17024-16823Fixed in: 1.18.2-9
microsoftpatch availablevia msrc
Product: 17025-16817Fixed in: 1.18.2-9
microsoftpatch availablevia msrc
Product: 17025-17084Fixed in: 1.18.2-9
microsoftpatch availablevia msrc
Product: cbl2 libtomcrypt 1.18.2-9 on CBL Mariner 2.0Fixed in: 1.18.2-9
microsoftpatch availablevia msrc
Product: azl3 libtomcrypt 1.18.2-9 on Azure Linux 3.0Fixed in: 1.18.2-9
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 x64Fixed in: 1.18.2-9
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 ARMFixed in: 1.18.2-9
microsoftpatch availablevia msrc
Product: Azure Linux 3.0 x64Fixed in: 1.18.2-9
microsoftpatch availablevia msrc
Product: Azure Linux 3.0 ARMFixed in: 1.18.2-9

Vendor Advisories (3)

microsoft2024-Jun/CVE-2019-17362

CVE-2019-17362

Jun 11, 2024
microsoft2019-Oct/CVE-2019-17362Critical

In LibTomCrypt through 1.18.2 the der_decode_utf8_string function (in der_decode_utf8_string.c) does not properly detect certain invalid UTF-8 sequences. This allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) or read information from other memory locations via carefully crafted DER-encoded data.

Oct 8, 2019
redhatCVE-2019-17362Moderate

libtomcrypt: out-of-bounds read in the der_decode_utf8_string function in der_decode_utf8_string.c

Aug 10, 2019

References

lists.fedoraproject.org / archives/list/[email protected]/message/47YP5SXQ4RY6KMTK2HI5ZZR244XKRMCZ
lists.fedoraproject.org / archives/list/[email protected]/message/YU5OMCY3PX54YVI4FMNDEENHDJZJ3RJW
lists.opensuse.org / opensuse-security-announce/2019-11/msg00020.html
lists.opensuse.org / opensuse-security-announce/2019-11/msg00041.html
github.com / libtom/libtomcrypt/issues/507
ExploitThird Party Advisory
github.com / libtom/libtomcrypt/pull/508
PatchThird Party Advisory
lists.debian.org / debian-lts-announce/2019/10/msg00010.html
Mailing ListThird Party Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/47YP5SXQ4RY6KMTK2HI5ZZR244XKRMCZ
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/YU5OMCY3PX54YVI4FMNDEENHDJZJ3RJW
vuldb.com
Permissions Required