Lucene search

K
rosalinuxROSA LABROSA-SA-2023-2194
HistoryJul 18, 2023 - 11:28 a.m.

Advisory ROSA-SA-2023-2194

2023-07-1811:28:24
ROSA LAB
abf.rosalinux.ru
7
libtasn1
vulnerability
remote disclosure
denial of service
resolved
update command
unix

9.1 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

0.004 Low

EPSS

Percentile

73.4%

Software: libtasn1 4.13
OS: ROSA Virtualization 2.1

package_evr_string: libtasn1-4.13-4.rv3.src.rpm

CVE-ID: CVE-2021-46848
BDU-ID: 2022-06694
CVE-Crit: HIGH
CVE-DESC.: A vulnerability in the asn1_encode_simple_der() function of the Libtasn1 library is related to a single offset error. Exploitation of the vulnerability could allow an attacker acting remotely to disclose protected information or cause a denial of service by transmitting specially crafted data to an application
CVE-STATUS: Resolved
CVE-REV: To close, run the yum update libtasn1 command.

OSVersionArchitecturePackageVersionFilename
ROSAanynoarchlibtasn1< 4.13UNKNOWN

9.1 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

0.004 Low

EPSS

Percentile

73.4%