CVE-2019-25219

unknown
Published — · Modified —
CVSS v3
CVSS v4 NEW
not yet in upstream
VIR risk

Description

Asio C++ Library before 1.13.0 lacks a fallback error code in the case of SSL_ERROR_SYSCALL with no associated error information from the SSL library being used.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Debian Security Tracker · View original ↗ · DFSG

CVE-2019-25219 NameCVE-2019-25219 DescriptionAsio C++ Library before 1.13.0 lacks a fallback error code in the case of SSL_ERROR_SYSCALL with no associated error information from the SSL library being used. SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) Vulnerable and fixed packages…

CVE-2019-25219

NameCVE-2019-25219
DescriptionAsio C++ Library before 1.13.0 lacks a fallback error code in the case of SSL_ERROR_SYSCALL with no associated error information from the SSL library being used.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
asio (PTS)bullseye1:1.18.1-1fixed
bookworm1:1.22.1-1fixed
forky, trixie1:1.30.2-1fixed
sid1:1.36.0-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
asiosource(unstable)1:1.18.1-1

Notes

Fixed by: https://github.com/chriskohlhoff/asio/commit/93337cba7b013150f5aa6194393e1d94be2853ec (asio-1-13-0)

Home - Debian Security - Source (Git)

Apply commands

text fix
Notes
Fixed by: https://github.com/chriskohlhoff/asio/commit/93337cba7b013150f5aa6194393e1d94be2853ec (asio-1-13-0)

OS impact

debian Debian Fixed 5 releases
VersionStatusFixed in
trixie Fixed 1:1.18.1-1
sid Fixed 1:1.18.1-1
forky Fixed 1:1.18.1-1
bullseye Fixed 1:1.18.1-1
bookworm Fixed 1:1.18.1-1

References

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.