Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-6003

Опубликовано: 22 янв. 2018
Источник: debian

Описание

An issue was discovered in the _asn1_decode_simple_ber function in decoding.c in GNU Libtasn1 before 4.13. Unlimited recursion in the BER decoder leads to stack exhaustion and DoS.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libtasn1-6fixed4.13-2package
libtasn1-6not-affectedjessiepackage
libtasn1-3not-affectedpackage

Примечания

  • https://lists.gnu.org/archive/html/help-libtasn1/2018-01/msg00000.html

  • Affected function introduced in: http://git.savannah.nongnu.org/cgit/libtasn1.git/commit/lib/decoding.c?id=b12bfa8932f44d1d1c25b4a2e385387a62dfbcc9 (libtasn1_4_3)

  • Fixed by: https://gitlab.com/gnutls/libtasn1/commit/c593ae84cfcde8fea45787e53950e0ac71e9ca97 (libtasn1_4_13)

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 8 лет назад

An issue was discovered in the _asn1_decode_simple_ber function in decoding.c in GNU Libtasn1 before 4.13. Unlimited recursion in the BER decoder leads to stack exhaustion and DoS.

CVSS3: 7.5
redhat
около 8 лет назад

An issue was discovered in the _asn1_decode_simple_ber function in decoding.c in GNU Libtasn1 before 4.13. Unlimited recursion in the BER decoder leads to stack exhaustion and DoS.

CVSS3: 7.5
nvd
около 8 лет назад

An issue was discovered in the _asn1_decode_simple_ber function in decoding.c in GNU Libtasn1 before 4.13. Unlimited recursion in the BER decoder leads to stack exhaustion and DoS.

suse-cvrf
около 8 лет назад

Security update for libtasn1

suse-cvrf
около 8 лет назад

Security update for libtasn1