Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-872v-39hw-4fr3

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The asn1_signature function in asn1.c in Cameron Hamilton-Rich axTLS through 2.1.5 has a Buffer Overflow that allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted certificate in the TLS certificate handshake message, because the result of get_asn1_length() is not checked for a minimum or maximum size.

The asn1_signature function in asn1.c in Cameron Hamilton-Rich axTLS through 2.1.5 has a Buffer Overflow that allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted certificate in the TLS certificate handshake message, because the result of get_asn1_length() is not checked for a minimum or maximum size.

EPSS

Процентиль: 78%
0.01186
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 6 лет назад

The asn1_signature function in asn1.c in Cameron Hamilton-Rich axTLS through 2.1.5 has a Buffer Overflow that allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted certificate in the TLS certificate handshake message, because the result of get_asn1_length() is not checked for a minimum or maximum size.

CVSS3: 7.5
nvd
около 6 лет назад

The asn1_signature function in asn1.c in Cameron Hamilton-Rich axTLS through 2.1.5 has a Buffer Overflow that allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted certificate in the TLS certificate handshake message, because the result of get_asn1_length() is not checked for a minimum or maximum size.

CVSS3: 7.5
debian
около 6 лет назад

The asn1_signature function in asn1.c in Cameron Hamilton-Rich axTLS t ...

EPSS

Процентиль: 78%
0.01186
Низкий