Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qg3j-x87h-jwjm

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The asn1_get_bit_der function in GNU Libtasn1 before 3.6 does not properly report an error when a negative bit length is identified, which allows context-dependent attackers to cause out-of-bounds access via crafted ASN.1 data.

The asn1_get_bit_der function in GNU Libtasn1 before 3.6 does not properly report an error when a negative bit length is identified, which allows context-dependent attackers to cause out-of-bounds access via crafted ASN.1 data.

EPSS

Процентиль: 91%
0.07656
Низкий

Дефекты

CWE-131

Связанные уязвимости

ubuntu
около 11 лет назад

The asn1_get_bit_der function in GNU Libtasn1 before 3.6 does not properly report an error when a negative bit length is identified, which allows context-dependent attackers to cause out-of-bounds access via crafted ASN.1 data.

redhat
около 11 лет назад

The asn1_get_bit_der function in GNU Libtasn1 before 3.6 does not properly report an error when a negative bit length is identified, which allows context-dependent attackers to cause out-of-bounds access via crafted ASN.1 data.

nvd
около 11 лет назад

The asn1_get_bit_der function in GNU Libtasn1 before 3.6 does not properly report an error when a negative bit length is identified, which allows context-dependent attackers to cause out-of-bounds access via crafted ASN.1 data.

debian
около 11 лет назад

The asn1_get_bit_der function in GNU Libtasn1 before 3.6 does not prop ...

oracle-oval
около 11 лет назад

ELSA-2014-0687: libtasn1 security update (MODERATE)

EPSS

Процентиль: 91%
0.07656
Низкий

Дефекты

CWE-131