Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-1000654

Опубликовано: 12 авг. 2018
Источник: redhat
CVSS3: 4
EPSS Низкий

Описание

GNU Libtasn1-4.13 libtasn1-4.13 version libtasn1-4.13, libtasn1-4.12 contains a DoS, specifically CPU usage will reach 100% when running asn1Paser against the POC due to an issue in _asn1_expand_object_id(p_tree), after a long time, the program will be killed. This attack appears to be exploitable via parsing a crafted file.

A vulnerability was found in GNU Libtasn1, where a resource management issue can lead to a denial of service, here an attacker could exploit this flaw by persuading a victim to parse a specially crafted file, exhausting all available CPU resources.

Отчет

This vulnerability is rated as low severity because it causes a denial of service by exhausting CPU resources, it impacts availability, it does not compromise system security or integrity. This flaw is in the asn1Parser binary included in libtasn1-tools RPM. The dynamic library libtasn1 and libtasn1-devel RPMs are not affected.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6libtasn1Will not fix
Red Hat Enterprise Linux 7libtasn1Will not fix
Red Hat Enterprise Linux 8libtasn1Will not fix
Red Hat Enterprise Linux 8mingw-libtasn1Fix deferred
Red Hat Satellite 6libtasn1Will not fix
Red Hat Virtualization 4libtasn1Will not fix

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-835
https://bugzilla.redhat.com/show_bug.cgi?id=1621972libtasn1: Infinite loop in _asn1_expand_object_id(ptree) leads to memory exhaustion

EPSS

Процентиль: 79%
0.02008
Низкий

4 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 8 лет назад

GNU Libtasn1-4.13 libtasn1-4.13 version libtasn1-4.13, libtasn1-4.12 contains a DoS, specifically CPU usage will reach 100% when running asn1Paser against the POC due to an issue in _asn1_expand_object_id(p_tree), after a long time, the program will be killed. This attack appears to be exploitable via parsing a crafted file.

CVSS3: 5.5
nvd
около 8 лет назад

GNU Libtasn1-4.13 libtasn1-4.13 version libtasn1-4.13, libtasn1-4.12 contains a DoS, specifically CPU usage will reach 100% when running asn1Paser against the POC due to an issue in _asn1_expand_object_id(p_tree), after a long time, the program will be killed. This attack appears to be exploitable via parsing a crafted file.

CVSS3: 5.5
debian
около 8 лет назад

GNU Libtasn1-4.13 libtasn1-4.13 version libtasn1-4.13, libtasn1-4.12 c ...

suse-cvrf
около 7 лет назад

Security update for libtasn1

suse-cvrf
около 7 лет назад

Security update for libtasn1

EPSS

Процентиль: 79%
0.02008
Низкий

4 Medium

CVSS3