PT-2023-27149 · Nlnet+1 · Bcder+1
Donika Mirdita
+2
·
Published
2023-09-13
·
Updated
2024-09-11
·
CVE-2023-39914
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
NLnet Labs' bcder library versions 0.7.2 and earlier
Description
The bcder library panics while decoding certain invalid input data rather than rejecting the data with an error. This can affect both the actual decoding stage as well as accessing content of types that utilized delayed decoding.
Recommendations
For versions 0.7.2 and earlier, update to version 0.7.3 or later, which fixes the issue by more thoroughly checking inputs and returning errors as expected. As a temporary workaround, consider implementing additional input validation to prevent the library from panicking when encountering invalid data.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Debian
Bcder