The _asn1_check_identifier function in GNU Libtasn1 through 4.12 causes a NULL pointer dereference and crash when reading crafted input that triggers assignment of a NULL value within an asn1_node structure. It may lead to a remote denial of service attack.
CVSS Details
- CVSS 3.0 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade libtasn1 | Sep 20, 2017 | Jul 2, 2017 |
| Debian | — | Upgrade libtasn1-3Upgrade libtasn1-6 | Feb 8, 2018 | Jul 1, 2017 |
| Gentoo Linux | — | Upgrade dev-libs/libtasn1. | Oct 30, 2017 | Jul 1, 2017 |
| Huawei Euleros 2_0_sp2 | — | Upgrade libtasn1Upgrade libtasn1-devel | Dec 4, 2019 | Jul 2, 2017 |
| Huawei Euleros 2_0_sp3 | — | Upgrade libtasn1Upgrade libtasn1-devel | Dec 18, 2019 | Jul 2, 2017 |
| Huawei Euleros 2_0_sp5 | — | Upgrade libtasn1-develUpgrade libtasn1 | Nov 19, 2019 | Jul 2, 2017 |
| Oracle Solaris | — | Upgrade entire/ to version 11.4-11.4.0.0.1.15.0 on Solaris 11.4 | Oct 19, 2018 | Jul 1, 2017 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jun 22, 2017 |
| Suse | — | Upgrade libgnutlsxx28Upgrade libgnutls-dane-develUpgrade libgnutls-extra26Upgrade libgnutls30Upgrade libgnutls-dane0Upgrade gnutlsUpgrade libgnutls-openssl-develUpgrade libgnutls-devel-32bitUpgrade libgnutls-openssl27Upgrade libgnutls-develUpgrade libgnutls28-32bitUpgrade libgnutls28Upgrade gnutls-guileUpgrade libgnutls30-32bitUpgrade libgnutlsxx-devel | Sep 25, 2018 | Jul 1, 2017 |
| Ubuntu | — | Upgrade libtasn1-6 | Jan 26, 2018 | Jul 1, 2017 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Jul 2, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub