Unrated severityNVD Advisory· Published Aug 20, 2018· Updated Aug 5, 2024
CVE-2018-1000654
CVE-2018-1000654
Description
GNU Libtasn1-4.13 libtasn1-4.13 version libtasn1-4.13, libtasn1-4.12 contains a DoS, specifically CPU usage will reach 100% when running asn1Paser against the POC due to an issue in _asn1_expand_object_id(p_tree), after a long time, the program will be killed. This attack appears to be exploitable via parsing a crafted file.
Affected products
15- osv-coords15 versionspkg:rpm/opensuse/libtasn1&distro=openSUSE%20Leap%2015.0pkg:rpm/opensuse/libtasn1&distro=openSUSE%20Leap%2015.1pkg:rpm/opensuse/libtasn1&distro=openSUSE%20Tumbleweedpkg:rpm/suse/libtasn1&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP3pkg:rpm/suse/libtasn1&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP4pkg:rpm/suse/libtasn1&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015pkg:rpm/suse/libtasn1&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP1pkg:rpm/suse/libtasn1&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015pkg:rpm/suse/libtasn1&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-BCLpkg:rpm/suse/libtasn1&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3pkg:rpm/suse/libtasn1&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP4pkg:rpm/suse/libtasn1&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP3pkg:rpm/suse/libtasn1&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP4pkg:rpm/suse/libtasn1&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP3pkg:rpm/suse/libtasn1&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP4
< 4.13-lp151.4.3.1+ 14 more
- (no CPE)range: < 4.13-lp151.4.3.1
- (no CPE)range: < 4.13-lp151.4.3.1
- (no CPE)range: < 4.17.0-1.2
- (no CPE)range: < 4.9-3.10.1
- (no CPE)range: < 4.9-3.10.1
- (no CPE)range: < 4.13-4.5.1
- (no CPE)range: < 4.13-4.5.1
- (no CPE)range: < 4.13-4.5.1
- (no CPE)range: < 3.7-13.7.1
- (no CPE)range: < 4.9-3.10.1
- (no CPE)range: < 4.9-3.10.1
- (no CPE)range: < 4.9-3.10.1
- (no CPE)range: < 4.9-3.10.1
- (no CPE)range: < 4.9-3.10.1
- (no CPE)range: < 4.9-3.10.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- lists.opensuse.org/opensuse-security-announce/2019-06/msg00009.htmlmitrevendor-advisoryx_refsource_SUSE
- lists.opensuse.org/opensuse-security-announce/2019-06/msg00018.htmlmitrevendor-advisoryx_refsource_SUSE
- www.securityfocus.com/bid/105151mitrevdb-entryx_refsource_BID
- gitlab.com/gnutls/libtasn1/issues/4mitrex_refsource_CONFIRM
- lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3Emitremailing-listx_refsource_MLIST
News mentions
0No linked articles in our index yet.