Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-12133

Опубликовано: 10 фев. 2025
Источник: redhat
CVSS3: 5.3

Описание

A flaw in libtasn1 causes inefficient handling of specific certificate data. When processing a large number of elements in a certificate, libtasn1 takes much longer than expected, which can slow down or even crash the system. This flaw allows an attacker to send a specially crafted certificate, causing a denial of service attack.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10libtasn1Affected
Red Hat Enterprise Linux 6libtasn1Out of support scope
Red Hat Enterprise Linux 7libtasn1Out of support scope
Red Hat OpenShift Container Platform 4rhcosFix deferred
Red Hat Enterprise Linux 8libtasn1FixedRHSA-2025:404923.04.2025
Red Hat Enterprise Linux 8libtasn1FixedRHSA-2025:404923.04.2025
Red Hat Enterprise Linux 9libtasn1FixedRHSA-2025:707713.05.2025
Red Hat Enterprise Linux 9libtasn1FixedRHSA-2025:707713.05.2025
Red Hat Enterprise Linux 9.4 Extended Update Supportlibtasn1FixedRHSA-2025:802120.05.2025
Red Hat Discovery 1.14registry.redhat.io/discovery/discovery-server-rhel9FixedRHSA-2025:838502.06.2025

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-407
https://bugzilla.redhat.com/show_bug.cgi?id=2344611libtasn1: Inefficient DER Decoding in libtasn1 Leading to Potential Remote DoS

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
6 месяцев назад

A flaw in libtasn1 causes inefficient handling of specific certificate data. When processing a large number of elements in a certificate, libtasn1 takes much longer than expected, which can slow down or even crash the system. This flaw allows an attacker to send a specially crafted certificate, causing a denial of service attack.

CVSS3: 5.3
nvd
6 месяцев назад

A flaw in libtasn1 causes inefficient handling of specific certificate data. When processing a large number of elements in a certificate, libtasn1 takes much longer than expected, which can slow down or even crash the system. This flaw allows an attacker to send a specially crafted certificate, causing a denial of service attack.

CVSS3: 5.3
msrc
5 месяцев назад

Описание отсутствует

CVSS3: 5.3
debian
6 месяцев назад

A flaw in libtasn1 causes inefficient handling of specific certificate ...

suse-cvrf
6 месяцев назад

Security update for libtasn1

5.3 Medium

CVSS3