GNU libtasn1
cpe:2.3:a:gnu:libtasn1:*:*:*:*:*:*:*
- <= 4.19.0
A denial-of-service vulnerability has been identified in GNU Libtasn1, a library for managing Abstract Syntax Notation One (ASN.1) data. This vulnerability affects all versions of Libtasn1 prior to 4.20.0. The issue arises from inefficient handling of certificates containing a large number of 'SEQUENCE OF' or 'SET OF' elements. When such a certificate is processed, the decoding time can increase significantly, leading to excessive CPU usage. This vulnerability can be exploited by sending a specially crafted certificate, causing applications that use Libtasn1 for certificate parsing and verification to slow down or crash.
Exploitation of this vulnerability can cause applications to hang or crash, leading to a denial-of-service condition.
The vulnerability can be reproduced by using the 'certtool' command-line utility included with GnuTLS. After upgrading to Libtasn1 version 4.20.0, the vulnerability no longer occurs.
Users are advised to upgrade to Libtasn1 version 4.20.0 or later. For those who cannot modify application code, operating system resource control mechanisms, such as cgroups, can help manage CPU usage.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.