Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-46848

Опубликовано: 24 окт. 2022
Источник: redhat
CVSS3: 5.9

Описание

GNU Libtasn1 before 4.19.0 has an ETYPE_OK off-by-one array size check that affects asn1_encode_simple_der.

An out-of-bounds read flaw was found in Libtasn1 due to an ETYPE_OK off-by-one error in the asn1_encode_simple_der() function. This flaw allows a remote attacker to pass specially crafted data or invalid values to the application, triggering an off-by-one error, corrupting the memory, and possibly performing a denial of service (DoS) attack.

Отчет

This flaw enables access to one additional memory byte, significantly constraining the potential damage an attacker could inflict. For this reason it is rated as having a Moderate impact to Red Hat Offerings.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6libtasn1Not affected
Red Hat Enterprise Linux 7libtasn1Out of support scope
Red Hat Satellite 6libtasn1Will not fix
Red Hat Enterprise Linux 8libtasn1FixedRHSA-2023:011612.01.2023
Red Hat Enterprise Linux 8libtasn1FixedRHSA-2023:011612.01.2023
Red Hat Enterprise Linux 8.6 Extended Update Supportlibtasn1FixedRHSA-2024:042725.01.2024
Red Hat Enterprise Linux 9libtasn1FixedRHSA-2023:034323.01.2023
Red Hat Enterprise Linux 9libtasn1FixedRHSA-2023:034323.01.2023

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-193->CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2140058libtasn1: Out-of-bound access in ETYPE_OK

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 9.1
ubuntu
больше 2 лет назад

GNU Libtasn1 before 4.19.0 has an ETYPE_OK off-by-one array size check that affects asn1_encode_simple_der.

CVSS3: 9.1
nvd
больше 2 лет назад

GNU Libtasn1 before 4.19.0 has an ETYPE_OK off-by-one array size check that affects asn1_encode_simple_der.

CVSS3: 9.1
msrc
больше 2 лет назад

Описание отсутствует

CVSS3: 9.1
debian
больше 2 лет назад

GNU Libtasn1 before 4.19.0 has an ETYPE_OK off-by-one array size check ...

suse-cvrf
больше 2 лет назад

Security update for libtasn1

5.9 Medium

CVSS3