Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-12133

Опубликовано: 10 фев. 2025
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

A flaw in libtasn1 causes inefficient handling of specific certificate data. When processing a large number of elements in a certificate, libtasn1 takes much longer than expected, which can slow down or even crash the system. This flaw allows an attacker to send a specially crafted certificate, causing a denial of service attack.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10libtasn1Affected
Red Hat Enterprise Linux 6libtasn1Out of support scope
Red Hat Enterprise Linux 7libtasn1Out of support scope
Red Hat OpenShift Container Platform 4rhcosFix deferred
Red Hat Enterprise Linux 8libtasn1FixedRHSA-2025:404923.04.2025
Red Hat Enterprise Linux 8libtasn1FixedRHSA-2025:404923.04.2025
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportgnutlsFixedRHSA-2026:3312529.06.2026
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Supportlibtasn1FixedRHSA-2026:3312529.06.2026
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-OngnutlsFixedRHSA-2026:3312529.06.2026
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-Onlibtasn1FixedRHSA-2026:3312529.06.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-407
https://bugzilla.redhat.com/show_bug.cgi?id=2344611libtasn1: Inefficient DER Decoding in libtasn1 Leading to Potential Remote DoS

EPSS

Процентиль: 61%
0.0107
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 1 года назад

A flaw in libtasn1 causes inefficient handling of specific certificate data. When processing a large number of elements in a certificate, libtasn1 takes much longer than expected, which can slow down or even crash the system. This flaw allows an attacker to send a specially crafted certificate, causing a denial of service attack.

CVSS3: 5.3
nvd
больше 1 года назад

A flaw in libtasn1 causes inefficient handling of specific certificate data. When processing a large number of elements in a certificate, libtasn1 takes much longer than expected, which can slow down or even crash the system. This flaw allows an attacker to send a specially crafted certificate, causing a denial of service attack.

CVSS3: 5.3
msrc
больше 1 года назад

Libtasn1: inefficient der decoding in libtasn1 leading to potential remote dos

CVSS3: 5.3
debian
больше 1 года назад

A flaw in libtasn1 causes inefficient handling of specific certificate ...

suse-cvrf
больше 1 года назад

Security update for libtasn1

EPSS

Процентиль: 61%
0.0107
Низкий

5.3 Medium

CVSS3