PT-2017-3258 · Gnu+3 · Gnu Libtasn1+3

Publicado

2017-06-22

·

Atualizado

2021-06-29

·

CVE-2017-10790

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions GNU Libtasn1 versions prior to 4.13
Description The issue is related to a NULL pointer dereference and crash in the asn1 check identifier function when reading crafted input. This may lead to a remote denial of service attack. The vulnerability is caused by errors in pointer dereferencing, specifically the lack of checking for a NULL value when reading the input stream.
Recommendations For GNU Libtasn1 versions prior to 4.13, update to version 4.13 or later to resolve the issue. As a temporary workaround, consider restricting the use of the asn1 check identifier function until a patch is available.

Exploit

Correção

DoS

NULL Pointer Dereference

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2018-1088
BDU:2018-00014
CVE-2017-10790
DLA-1038-1
DLA-2255-1
DSA-4106-1
MGASA-2018-0121
OPENSUSE-SU-2018_2854-1
OPENSUSE-SU-2018_2958-1
SUSE-SU-2018:2825-1
SUSE-SU-2018:2825-2
SUSE-SU-2018:2842-1
SUSE-SU-2018:2930-1
SUSE-SU-2018_2825-1
SUSE-SU-2018_2825-2
SUSE-SU-2018_2842-1
SUSE-SU-2018_2930-1
SUSE-SU-2019:14058-1
SUSE-SU-2019_14058-1
USN-3547-1

Produtos afetados

Alt Linux
Gnu Libtasn1
Suse
Ubuntu