Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-1000654

Опубликовано: 12 авг. 2018
Источник: redhat
CVSS3: 4
EPSS Низкий

Описание

GNU Libtasn1-4.13 libtasn1-4.13 version libtasn1-4.13, libtasn1-4.12 contains a DoS, specifically CPU usage will reach 100% when running asn1Paser against the POC due to an issue in _asn1_expand_object_id(p_tree), after a long time, the program will be killed. This attack appears to be exploitable via parsing a crafted file.

Отчет

This vulnerability is rated as low severity because it causes a denial of service by exhausting CPU resources, it impacts availability, it does not compromise system security or integrity. This flaw is in the asn1Parser binary included in libtasn1-tools RPM. The dynamic library libtasn1 and libtasn1-devel RPMs are not affected.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6libtasn1Will not fix
Red Hat Enterprise Linux 7libtasn1Will not fix
Red Hat Enterprise Linux 8libtasn1Will not fix
Red Hat Enterprise Linux 8mingw-libtasn1Fix deferred
Red Hat Satellite 6libtasn1Will not fix
Red Hat Virtualization 4libtasn1Will not fix

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-20->CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=1621972libtasn1: Infinite loop in _asn1_expand_object_id(ptree) leads to memory exhaustion

EPSS

Процентиль: 32%
0.00125
Низкий

4 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 7 лет назад

GNU Libtasn1-4.13 libtasn1-4.13 version libtasn1-4.13, libtasn1-4.12 contains a DoS, specifically CPU usage will reach 100% when running asn1Paser against the POC due to an issue in _asn1_expand_object_id(p_tree), after a long time, the program will be killed. This attack appears to be exploitable via parsing a crafted file.

CVSS3: 5.5
nvd
больше 7 лет назад

GNU Libtasn1-4.13 libtasn1-4.13 version libtasn1-4.13, libtasn1-4.12 contains a DoS, specifically CPU usage will reach 100% when running asn1Paser against the POC due to an issue in _asn1_expand_object_id(p_tree), after a long time, the program will be killed. This attack appears to be exploitable via parsing a crafted file.

CVSS3: 5.5
debian
больше 7 лет назад

GNU Libtasn1-4.13 libtasn1-4.13 version libtasn1-4.13, libtasn1-4.12 c ...

suse-cvrf
больше 6 лет назад

Security update for libtasn1

suse-cvrf
больше 6 лет назад

Security update for libtasn1

EPSS

Процентиль: 32%
0.00125
Низкий

4 Medium

CVSS3