CVE-2017-10790 PUBLISHED

The _asn1_check_identifier function in GNU Libtasn1 through 4.12 causes a NULL pointer dereference and crash when reading crafted input that triggers assignment of a NULL value within an asn1_node structure. It may lead to a remote denial of service attack.

EPSS 0.39% · 60.1th percentile

Risk Scores

EPSS Score
0.39%
60.1th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSlibtasn1-60, 4.5-2, 4.7-2
Ubuntu:14.04:LTSlibtasn1-63.4-3ubuntu0.3, 0, 3.4-3ubuntu0.5

Timeline

References

Open in Interactive Console →