CVE-2018-1000654

Published: 20 August 2018

GNU Libtasn1-4.13 libtasn1-4.13 version libtasn1-4.13, libtasn1-4.12 contains a DoS, specifically CPU usage will reach 100% when running asn1Paser against the POC due to an issue in _asn1_expand_object_id(p_tree), after a long time, the program will be killed. This attack appears to be exploitable via parsing a crafted file.

Priority

Negligible

CVSS 3 base score: 5.5

Status

Package Release Status
libtasn1-3
Launchpad, Ubuntu, Debian
Upstream Needs triage

Ubuntu 20.10 (Groovy Gorilla) Does not exist

Ubuntu 20.04 LTS (Focal Fossa) Does not exist

Ubuntu 18.04 LTS (Bionic Beaver) Does not exist

Ubuntu 16.04 LTS (Xenial Xerus) Does not exist

Ubuntu 14.04 ESM (Trusty Tahr) Does not exist

libtasn1-6
Launchpad, Ubuntu, Debian
Upstream Needs triage

Ubuntu 20.10 (Groovy Gorilla) Deferred
(2018-10-09)
Ubuntu 20.04 LTS (Focal Fossa) Deferred
(2018-10-09)
Ubuntu 18.04 LTS (Bionic Beaver) Deferred
(2018-10-09)
Ubuntu 16.04 LTS (Xenial Xerus) Deferred
(2018-10-09)
Ubuntu 14.04 ESM (Trusty Tahr) Deferred
(2018-10-09)

Notes

AuthorNote
mdeslaur
only an issue during at build time, not at runtime. As such,
marking as negigible
leosilva
no upstream fix as of 2018-10-09

References

Bugs