PT-2023-27149 · Nlnet+1 · Bcder+1

Donika Mirdita

+2

·

Publicado

2023-09-13

·

Atualizado

2024-09-11

·

CVE-2023-39914

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions NLnet Labs' bcder library versions 0.7.2 and earlier
Description The bcder library panics while decoding certain invalid input data rather than rejecting the data with an error. This can affect both the actual decoding stage as well as accessing content of types that utilized delayed decoding.
Recommendations For versions 0.7.2 and earlier, update to version 0.7.3 or later, which fixes the issue by more thoroughly checking inputs and returning errors as expected. As a temporary workaround, consider implementing additional input validation to prevent the library from panicking when encountering invalid data.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-39914
GHSA-6JMW-6MXW-W4JC
RUSTSEC-2023-0062

Produtos afetados

Debian
Bcder