CVE-2018-6003
Published: 22 January 2018
An issue was discovered in the _asn1_decode_simple_ber function in decoding.c in GNU Libtasn1 before 4.13. Unlimited recursion in the BER decoder leads to stack exhaustion and DoS.
Priority
CVSS 3 base score: 7.5
Status
Package | Release | Status |
---|---|---|
libtasn1-3 Launchpad, Ubuntu, Debian |
Upstream |
Needs triage
|
Ubuntu 18.04 LTS (Bionic Beaver) |
Does not exist
|
|
Ubuntu 16.04 LTS (Xenial Xerus) |
Does not exist
|
|
Ubuntu 14.04 ESM (Trusty Tahr) |
Does not exist
|
|
libtasn1-6 Launchpad, Ubuntu, Debian |
Upstream |
Released
(4.13-2)
|
Ubuntu 18.04 LTS (Bionic Beaver) |
Not vulnerable
|
|
Ubuntu 16.04 LTS (Xenial Xerus) |
Released
(4.7-3ubuntu0.16.04.3)
|
|
Ubuntu 14.04 ESM (Trusty Tahr) |
Not vulnerable
|
Notes
Author | Note |
---|---|
leosilva | libtasn1-3 (precise) and libtasn1-6 (trusty) are not affected since vulnerable code was introduced in 4.3 bionic already has the fix |
References
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-6003
- http://git.savannah.nongnu.org/cgit/libtasn1.git/commit/?id=c593ae84cfcde8fea45787e53950e0ac71e9ca97
- https://bugzilla.redhat.com/show_bug.cgi?id=1535926
- https://bugzilla.suse.com/show_bug.cgi?id=1076832
- https://gitlab.com/gnutls/libtasn1/commit/946565d8eb05fbf7970ea366e817581bb5a90910
- https://usn.ubuntu.com/usn/usn-3547-1
- NVD
- Launchpad
- Debian