Resource exhaustion in libtASN1 - CVE-2018-6003

 

Resource exhaustion in libtASN1 - CVE-2018-6003

Published: January 29, 2018


Vulnerability identifier: #VU10323
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-6003
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause DoS condition on the target system.

The weakness exists in the _asn1_decode_simple_ber function in decoding.c in GNU Libtasn1. A remote attacker can trigger unlimited recursion in the BER decoder and stack exhaustion to cause the service to crash.

Affected software

libtASN1
Debian Linux
Ubuntu
Fedora
libtasn1 (Alpine package)
libtasn1
mingw-libtasn1

How to mitigate CVE-2018-6003

Update to version 4.13 or later.

libtasn1 (Alpine package) - update to 4.8-r3
libtasn1 - addressed in versions 4.13-1.fc26, 4.13-1.fc27
mingw-libtasn1 - update to 4.13-1.fc27

External References

Related Security Bulletins