Lucene search

K
ubuntucveUbuntu.comUB:CVE-2021-46848
HistoryOct 25, 2022 - 12:00 a.m.

CVE-2021-46848

2022-10-2500:00:00
ubuntu.com
ubuntu.com
44
gnu libtasn1
etype_ok
array size check
asn1_encode_simple_der
vulnerability
cve-2021-46848
security bug
gnutls
gentoo
out of bounds read
api
invalid value

9.1 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

0.004 Low

EPSS

Percentile

73.4%

GNU Libtasn1 before 4.19.0 has an ETYPE_OK off-by-one array size check that
affects asn1_encode_simple_der.

Bugs

Notes

Author Note
mdeslaur out of bounds read in API when using invalid value, not likely to be exploitable in any way

9.1 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

0.004 Low

EPSS

Percentile

73.4%