CVE-2018-6003
Publication date 22 January 2018
Last updated 24 July 2024
Ubuntu priority
Cvss 3 Severity Score
An issue was discovered in the _asn1_decode_simple_ber function in decoding.c in GNU Libtasn1 before 4.13. Unlimited recursion in the BER decoder leads to stack exhaustion and DoS.
Status
Package | Ubuntu Release | Status |
---|---|---|
libtasn1-3 | ||
16.04 LTS xenial | Not in release | |
14.04 LTS trusty | Not in release | |
libtasn1-6 | ||
16.04 LTS xenial |
Fixed 4.7-3ubuntu0.16.04.3
|
|
14.04 LTS trusty |
Not affected
|
Notes
leosilva
libtasn1-3 (precise) and libtasn1-6 (trusty) are not affected since vulnerable code was introduced in 4.3 bionic already has the fix
Severity score breakdown
Parameter | Value |
---|---|
Base score | 7.5 · High |
Attack vector | Network |
Attack complexity | Low |
Privileges required | None |
User interaction | None |
Scope | Unchanged |
Confidentiality | None |
Integrity impact | None |
Availability impact | High |
Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
References
Related Ubuntu Security Notices (USN)
- USN-3547-1
- Libtasn1 vulnerabilities
- 25 January 2018
Other references
- http://git.savannah.nongnu.org/cgit/libtasn1.git/commit/?id=c593ae84cfcde8fea45787e53950e0ac71e9ca97
- https://bugzilla.redhat.com/show_bug.cgi?id=1535926
- https://bugzilla.suse.com/show_bug.cgi?id=1076832
- https://gitlab.com/gnutls/libtasn1/commit/946565d8eb05fbf7970ea366e817581bb5a90910
- https://www.cve.org/CVERecord?id=CVE-2018-6003