Resource exhaustion in libtASN1 - CVE-2018-6003
Published: January 29, 2018
Vulnerability identifier: #VU10323
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-6003
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to cause DoS condition on the target system.
The weakness exists in the _asn1_decode_simple_ber function in decoding.c in GNU Libtasn1. A remote attacker can trigger unlimited recursion in the BER decoder and stack exhaustion to cause the service to crash.
The weakness exists in the _asn1_decode_simple_ber function in decoding.c in GNU Libtasn1. A remote attacker can trigger unlimited recursion in the BER decoder and stack exhaustion to cause the service to crash.
Affected software
libtASN1
Debian Linux
Ubuntu
Fedora
libtasn1 (Alpine package)
libtasn1
mingw-libtasn1
Debian Linux
Ubuntu
Fedora
libtasn1 (Alpine package)
libtasn1
mingw-libtasn1
How to mitigate CVE-2018-6003
Update to version 4.13 or later.
libtasn1 (Alpine package) - update to 4.8-r3
libtasn1 - addressed in versions 4.13-1.fc26, 4.13-1.fc27
mingw-libtasn1 - update to 4.13-1.fc27
libtasn1 - addressed in versions 4.13-1.fc26, 4.13-1.fc27
mingw-libtasn1 - update to 4.13-1.fc27