445
VMScore

CVE-2018-6003

Published: 22/01/2018 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

An issue exists in the _asn1_decode_simple_ber function in decoding.c in GNU Libtasn1 prior to 4.13. Unlimited recursion in the BER decoder leads to stack exhaustion and DoS.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

gnu libtasn1

fedoraproject fedora 26

debian debian linux 9.0

fedoraproject fedora 27

Vendor Advisories

Debian Bug report logs - #867398 libtasn1-6: CVE-2017-10790 Package: src:libtasn1-6; Maintainer for src:libtasn1-6 is Debian GnuTLS Maintainers <pkg-gnutls-maint@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 6 Jul 2017 12:54:02 UTC Severity: normal Tags: patch, security, ...
Several security issues were fixed in Libtasn1 ...
An issue was discovered in the _asn1_decode_simple_ber function in decodingc in GNU Libtasn1 before 413 Unlimited recursion in the BER decoder leads to stack exhaustion and DoS ...