Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jcv4-2hjq-vv2c

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The asn1_get_length_der function in decoding.c in GNU Libtasn1 before 2.12, as used in GnuTLS before 3.0.16 and other products, does not properly handle certain large length values, which allows remote attackers to cause a denial of service (heap memory corruption and application crash) or possibly have unspecified other impact via a crafted ASN.1 structure.

The asn1_get_length_der function in decoding.c in GNU Libtasn1 before 2.12, as used in GnuTLS before 3.0.16 and other products, does not properly handle certain large length values, which allows remote attackers to cause a denial of service (heap memory corruption and application crash) or possibly have unspecified other impact via a crafted ASN.1 structure.

Ссылки

EPSS

Процентиль: 93%
0.10039
Средний

Связанные уязвимости

ubuntu
больше 13 лет назад

The asn1_get_length_der function in decoding.c in GNU Libtasn1 before 2.12, as used in GnuTLS before 3.0.16 and other products, does not properly handle certain large length values, which allows remote attackers to cause a denial of service (heap memory corruption and application crash) or possibly have unspecified other impact via a crafted ASN.1 structure.

redhat
больше 13 лет назад

The asn1_get_length_der function in decoding.c in GNU Libtasn1 before 2.12, as used in GnuTLS before 3.0.16 and other products, does not properly handle certain large length values, which allows remote attackers to cause a denial of service (heap memory corruption and application crash) or possibly have unspecified other impact via a crafted ASN.1 structure.

nvd
больше 13 лет назад

The asn1_get_length_der function in decoding.c in GNU Libtasn1 before 2.12, as used in GnuTLS before 3.0.16 and other products, does not properly handle certain large length values, which allows remote attackers to cause a denial of service (heap memory corruption and application crash) or possibly have unspecified other impact via a crafted ASN.1 structure.

debian
больше 13 лет назад

The asn1_get_length_der function in decoding.c in GNU Libtasn1 before ...

oracle-oval
больше 13 лет назад

ELSA-2012-0427: libtasn1 security update (IMPORTANT)

EPSS

Процентиль: 93%
0.10039
Средний