PT-2023-27149 · Nlnet+1 · Bcder+1

Donika Mirdita

+2

·

Published

2023-09-13

·

Updated

2024-09-11

·

CVE-2023-39914

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions NLnet Labs' bcder library versions 0.7.2 and earlier
Description The bcder library panics while decoding certain invalid input data rather than rejecting the data with an error. This can affect both the actual decoding stage as well as accessing content of types that utilized delayed decoding.
Recommendations For versions 0.7.2 and earlier, update to version 0.7.3 or later, which fixes the issue by more thoroughly checking inputs and returning errors as expected. As a temporary workaround, consider implementing additional input validation to prevent the library from panicking when encountering invalid data.

Fix

Weakness Enumeration

Related Identifiers

CVE-2023-39914
GHSA-6JMW-6MXW-W4JC
RUSTSEC-2023-0062

Affected Products

Debian
Bcder