Bug 1473192 - (CVE-2017-10790) CVE-2017-10790 libtasn1: NULL pointer dereference in the _asn1_check_identifier function
CVE-2017-10790 libtasn1: NULL pointer dereference in the _asn1_check_identifi...
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
All Linux
low Severity low
: ---
: ---
Assigned To: Red Hat Product Security
: Security
Depends On: 1473194 1473196 1473195
  Show dependency treegraph
Reported: 2017-07-20 04:23 EDT by Andrej Nemec
Modified: 2017-07-20 04:27 EDT (History)
20 users (show)

See Also:
Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of:
Last Closed: 2017-07-20 04:27:07 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Attachments (Terms of Use)

  None (edit)
Description Andrej Nemec 2017-07-20 04:23:14 EDT
The _asn1_check_identifier function in GNU Libtasn1 causes a NULL pointer dereference and crash when reading crafted input that triggers assignment of a NULL value within an asn1_node structure. It may lead to a denial of service attack.

Product bug:

Comment 1 Andrej Nemec 2017-07-20 04:23:55 EDT
Created libtasn1 tracking bugs for this issue:

Affects: fedora-all [bug 1473195]

Created mingw-libtasn1 tracking bugs for this issue:

Affects: epel-7 [bug 1473196]
Affects: fedora-all [bug 1473194]

Note You need to log in before you can comment on or make changes to this bug.