CVE-2018-1000654 PUBLISHED

GNU Libtasn1-4.13 libtasn1-4.13 version libtasn1-4.13, libtasn1-4.12 contains a DoS, specifically CPU usage will reach 100% when running asn1Paser against the POC due to an issue in _asn1_expand_object_id(p_tree), after a long time, the program will be killed. This attack appears to be exploitable via parsing a crafted file.

EPSS 0.12% · 31.6th percentile

Risk Scores

EPSS Score
0.12%
31.6th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:14.04:LTSlibtasn1-60, 3.3-2, 3.4-2
Ubuntu:Pro:16.04:LTSlibtasn1-60, 4.5-2, 4.7-2
Ubuntu:Pro:18.04:LTSlibtasn1-60, 4.12-2.1, 4.12-3

Timeline

References

Open in Interactive Console →