PT-2021-24285 · Unknown · Simple Asn1

Published

2021-11-14

·

Updated

2022-07-12

·

CVE-2021-45711

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: simple asn1 versions 0.6.0
Description: An issue was discovered in the simple asn1 crate where a panic occurs if UTCTime data, supplied by a remote attacker, has a second character greater than 0x7f. This happens when parsing the old ASN.1 "UTCTime" time format, and a string slice operation in the from der function tries to slice into the middle of a UTF-8 character, causing a panic. The issue is considered a security vulnerability because the crate is frequently used with inputs from the network.
Recommendations: For simple asn1 version 0.6.0, update to version 0.6.1 to resolve the issue. As a temporary workaround, consider restricting the use of the from der function and the der decode function until the patch is applied. Avoid using the simple asn1 crate with untrusted inputs from the network until the issue is resolved.

Fix

RCE

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-45711
GHSA-3M6F-3GFG-4X56
GHSA-G4H2-4WVH-GRC5
RUSTSEC-2021-0125

Affected Products

Simple Asn1