Input validation error in libtASN1 - CVE-2018-1000654

 

Input validation error in libtASN1 - CVE-2018-1000654

Published: April 17, 2019 / Updated: February 2, 2020


Vulnerability identifier: #VU18290
CSH Severity: Low
CVSS v4: 5.9 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-1000654
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of user-supplied input within the _asn1_expand_object_id(p_tree) function when parsing a specially crafted file with asn1Parser binary. An attacker can create a specially crafted file, pass it to the application and consume all available CPU resources on the system.


Affected software

libtASN1
VMware Tanzu Application Service for VMs
Juniper Cloud Native Router
Tanzu Greenplum for Kubernetes
VMware Tanzu Operations Manager
libtasn1 (Alpine package)
libtasn1
libtasn1-6
libtasn1-6-32bit
libtasn1-6-debuginfo
libtasn1-6-debuginfo-32bit
libtasn1-debuginfo
libtasn1-debugsource
libtasn1-bin (Ubuntu package)
libtasn1-6 (Ubuntu package)
SUSE Linux Enterprise Server
Opensuse
Ubuntu
Junos cRPD

How to mitigate CVE-2018-1000654

Install update from vendor's website.

libtASN1 - update to 4.14
Tanzu Greenplum for Kubernetes - update to 2.0.0
VMware Tanzu Operations Manager - addressed in versions 2.9.38, 2.10.39
libtasn1 (Alpine package) - addressed in versions 4.12-r4, 4.14-r0
libtasn1 - update to 3.7-13.7.1
libtasn1-6 - update to 3.7-13.7.1
libtasn1-6-32bit - update to 3.7-13.7.1
libtasn1-6-debuginfo - update to 3.7-13.7.1
libtasn1-6-debuginfo-32bit - update to 3.7-13.7.1
libtasn1-debuginfo - update to 3.7-13.7.1
libtasn1-debugsource - update to 3.7-13.7.1
libtasn1-bin (Ubuntu package) - update to 4.73ubuntu0.16.04.3+esm2
libtasn1-6 (Ubuntu package) - update to 4.73ubuntu0.16.04.3+esm2
Juniper Cloud Native Router - update to 23.4R1
Junos cRPD - update to 23.4R1

External References

Related Security Bulletins