[Forgot Password]
Login  Register Subscribe

30480

 
 

423868

 
 

253390

 
 

909

 
 

197257

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

[3.10] libtasn1: Infinite loop in _asn1_expand_object_id(ptree) leads to memory exhaustion (CVE-2018-1000654)

ID: oval:org.secpod.oval:def:1801512Date: (C)2019-07-22   (M)2023-11-10
Class: PATCHFamily: unix




The ASN.1 library used in GNUTLS through versions 4.13 allows for an infinite loop due to an issue in the _asn1_expand_object_id function. An attacker could exploit this via a crafted ASN.1 structure to causing high CPU usage until a resultant out-of-memory error

Platform:
Alpine Linux 3.10
Product:
libtasn1
Reference:
10518
CVE-2018-1000654
CVE    1
CVE-2018-1000654

© SecPod Technologies