Описание
By sending a deeply nested ASN1 structure to a Apache Kerby client or service, it's possible to trigger a StackOverFlow Exception which can lead to denial of service issues. Users are recommended to upgrade to version 2.1.2, which fixes this issue.
A flaw was found in Apache Kerby. A remote attacker could send a deeply nested Abstract Syntax Notation One (ASN.1) structure to an Apache Kerby client or service, triggering a stack overflow exception. This could lead to a denial of service (DoS) condition, making the service unavailable to legitimate users.
Отчет
This Moderate flaw in Apache Kerby, as used in several Red Hat products, allows a remote attacker to trigger a denial of service. By sending a specially crafted, deeply nested ASN.1 structure to a vulnerable client or service, an attacker can cause a stack overflow, leading to service unavailability. This impact is considered Moderate due to the potential for disruption of critical services.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat AMQ Clients | kerby-asn1 | Fix deferred | ||
| Red Hat Build of Keycloak | kerby-asn1 | Fix deferred | ||
| Red Hat Build of Keycloak | rhbk/keycloak-rhel9 | Fix deferred | ||
| Red Hat Build of Keycloak | rhbk-openshift-rhel9/rhbk-openshift-rhel9 | Fix deferred | ||
| Red Hat Data Grid 8 | kerby-asn1 | Fix deferred | ||
| Red Hat Fuse 7 | kerby-asn1 | Fix deferred | ||
| Red Hat JBoss Enterprise Application Platform Expansion Pack | kerby-asn1 | Fix deferred | ||
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-spark-operator-rhel9 | Fix deferred | ||
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-th06-cpu-torch210-py312-rhel9 | Fix deferred | ||
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-th06-cpu-torch291-py312-rhel9 | Fix deferred |
Показывать по
Дополнительная информация
Статус:
6.5 Medium
CVSS3
Связанные уязвимости
By sending a deeply nested ASN1 structure to a Apache Kerby client or service, it's possible to trigger a StackOverFlow Exception which can lead to denial of service issues. Users are recommended to upgrade to version 2.1.2, which fixes this issue.
By sending a deeply nested ASN1 structure to a Apache Kerby client or service, it's possible to trigger a StackOverFlow Exception which can lead to denial of service issues. Users are recommended to upgrade to version 2.1.2, which fixes this issue.
6.5 Medium
CVSS3