Denial of Service Vulnerability in GNU Libtasn1 Decoder Function
CVE-2018-6003
7.5HIGH
Summary
A flaw in the _asn1_decode_simple_ber function in GNU Libtasn1 versions before 4.13 allows an attacker to exploit the BER decoder, causing unlimited recursion and resulting in stack exhaustion. This vulnerability can lead to a Denial of Service condition, disrupting the operation of applications relying on the affected library.
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved