SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2012-1569

The asn1_get_length_der function in decoding.c in GNU Libtasn1 before 2.12, as used in GnuTLS before 3.0.16 and other products, does not properly handle certain large length values, which allows remote attackers to cause a denial of service (heap memory…

MEDIUM 5.0EPSS 4.41%

Does this matter?

Lower severity and a low EPSS score (4.41%). Track it; it rarely justifies an emergency change on its own.

Description

The asn1_get_length_der function in decoding.c in GNU Libtasn1 before 2.12, as used in GnuTLS before 3.0.16 and other products, does not properly handle certain large length values, which allows remote attackers to cause a denial of service (heap memory corruption and application crash) or possibly have unspecified other impact via a crafted ASN.1 structure.

CVSS 2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
EPSS
4.41% probability · 91th percentile
CISA KEV
Not listed
Weakness
CWE-189
Affected
gnu/gnutls · gnu/libtasn1
Source
secalert@redhat.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.