CVE-2018-6003
Summary
| CVE | CVE-2018-6003 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-01-22 20:29:00 UTC |
| Updated | 2023-11-07 02:58:00 UTC |
| Description | An issue was discovered in the _asn1_decode_simple_ber function in decoding.c in GNU Libtasn1 before 4.13. Unlimited recursion in the BER decoder leads to stack exhaustion and DoS. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [bookkeeper-issues] 20210628 [GitHub] [bookkeeper] padma81 opened a new issue #2746: Security Vulnerabilities in CentOS 7 image, Upgrade image to CentOS 8 |
|
lists.apache.org |
|
| released 4.13 (946565d8) · Commits · gnutls / libtasn1 · GitLab |
CONFIRM |
gitlab.com |
Third Party Advisory |
| Pony Mail! |
MLIST |
lists.apache.org |
|
| Debian -- Security Information -- DSA-4106-1 libtasn1-6 |
DEBIAN |
www.debian.org |
Third Party Advisory |
| libtasn1.git - GNU libtasn1 |
CONFIRM |
git.savannah.nongnu.org |
Patch, Vendor Advisory |
| Bug 1076832 – VUL-0: CVE-2018-6003: libtasn1: Stack exhaustion due to indefinite recursion during BER decoding |
CONFIRM |
bugzilla.suse.com |
Issue Tracking, Third Party Advisory |
| Pony Mail! |
MLIST |
lists.apache.org |
|
| [bookkeeper-issues] 20210629 [GitHub] [bookkeeper] padma81 opened a new issue #2746: Security Vulnerabilities in CentOS 7 image, Upgrade image to CentOS 8 |
|
lists.apache.org |
|
| Bug Access Denied |
CONFIRM |
bugzilla.redhat.com |
Issue Tracking, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 500322 Alpine Linux Security Update for libtasn1
- 504089 Alpine Linux Security Update for libtasn1