GNU Libtasn1-4.13 libtasn1-4.13 version libtasn1-4.13, libtasn1-4.12 contains a DoS, specifically CPU usage will reach 100% when running asn1Paser against the POC due to an issue in _asn1_expand_object_id(p_tree), after a long time, the program will be killed. This attack appears to be exploitable via parsing a crafted file.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | alpine-linux-upgrade-libtasn1 | Nov 8, 2019 | Aug 20, 2018 | |
| Redhat_linux | no-fix-redhat-rpm-package | Jul 9, 2025 | Aug 20, 2018 | |
| Suse | — | suse-upgrade-libtasn1suse-upgrade-libtasn1-6suse-upgrade-libtasn1-6-32bitsuse-upgrade-libtasn1-develsuse-upgrade-libtasn1-devel-32bit | May 30, 2019 | Aug 20, 2018 |
| Ubuntu | ubuntu-pro-upgrade-libtasn1-6ubuntu-pro-upgrade-libtasn1-bin | Mar 29, 2022 | Aug 20, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub