Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-10013

Опубликовано: 03 дек. 2019
Источник: nvd
CVSS3: 7.5
CVSS2: 7.8
EPSS Низкий

Описание

The asn1_signature function in asn1.c in Cameron Hamilton-Rich axTLS through 2.1.5 has a Buffer Overflow that allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted certificate in the TLS certificate handshake message, because the result of get_asn1_length() is not checked for a minimum or maximum size.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:axtls_project:axtls:*:*:*:*:*:*:*:*
Версия до 2.1.5 (включая)

EPSS

Процентиль: 78%
0.01186
Низкий

7.5 High

CVSS3

7.8 High

CVSS2

Дефекты

CWE-120

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 6 лет назад

The asn1_signature function in asn1.c in Cameron Hamilton-Rich axTLS through 2.1.5 has a Buffer Overflow that allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted certificate in the TLS certificate handshake message, because the result of get_asn1_length() is not checked for a minimum or maximum size.

CVSS3: 7.5
debian
около 6 лет назад

The asn1_signature function in asn1.c in Cameron Hamilton-Rich axTLS t ...

github
больше 3 лет назад

The asn1_signature function in asn1.c in Cameron Hamilton-Rich axTLS through 2.1.5 has a Buffer Overflow that allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted certificate in the TLS certificate handshake message, because the result of get_asn1_length() is not checked for a minimum or maximum size.

EPSS

Процентиль: 78%
0.01186
Низкий

7.5 High

CVSS3

7.8 High

CVSS2

Дефекты

CWE-120