Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

update: libtasn1 #1644

Open
dongsupark opened this issue Feb 12, 2025 · 0 comments
Open

update: libtasn1 #1644

dongsupark opened this issue Feb 12, 2025 · 0 comments
Labels
advisory security advisory cvss/MEDIUM >= 4 && < 7 assessed CVSS security security concerns

Comments

@dongsupark
Copy link
Member

Name: libtasn1
CVEs: CVE-2024-12133
CVSSs: 5.3
Action Needed: update to >= 4.20.0

Summary: A flaw in libtasn1 causes inefficient handling of specific certificate data. When processing a large number of elements in a certificate, libtasn1 takes much longer than expected, which can slow down or even crash the system. This flaw allows an attacker to send a specially crafted certificate, causing a denial of service attack.

See also https://bugzilla.redhat.com/show_bug.cgi?id=2344611.

refmap.gentoo: https://bugs.gentoo.org/949497

@dongsupark dongsupark added advisory security advisory cvss/MEDIUM >= 4 && < 7 assessed CVSS security security concerns labels Feb 12, 2025
@dongsupark dongsupark moved this from 📝 Needs Triage to 🪵Backlog in Flatcar tactical, release planning, and roadmap Feb 12, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
advisory security advisory cvss/MEDIUM >= 4 && < 7 assessed CVSS security security concerns
Projects
Development

No branches or pull requests

1 participant