Vulnerability CVE-2021-46848: Information

Description

GNU Libtasn1 before 4.19.0 has an ETYPE_OK off-by-one array size check that affects asn1_encode_simple_der.

Severity: CRITICAL (9.1) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

Published: Oct. 24, 2022
Modified: Nov. 7, 2023
Error type identifier: CWE-193

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
libtasn1sisyphus4.19.0-alt14.19.0-alt3ALT-PU-2022-2488-1305700Fixed
libtasn1sisyphus_e2k4.19.0-alt14.19.0-alt3ALT-PU-2022-5930-1-Fixed
libtasn1sisyphus_riscv644.19.0-alt14.19.0-alt3ALT-PU-2022-5829-1-Fixed
libtasn1p104.19.0-alt14.19.0-alt1ALT-PU-2022-3082-1309071Fixed
libtasn1p10_e2k4.19.0-alt14.19.0-alt1ALT-PU-2022-7077-1-Fixed
libtasn1c10f14.19.0-alt14.19.0-alt1ALT-PU-2022-3082-1309071Fixed
libtasn1c9f24.14-alt1.c9f2.14.14-alt1.c9f2.1ALT-PU-2023-1076-1313110Fixed
libtasn1p114.19.0-alt14.19.0-alt3ALT-PU-2022-2488-1305700Fixed

References to Advisories, Solutions, and Tools

    1. Configuration 1

      cpe:2.3:a:gnu:libtasn1:*:*:*:*:*:*:*:*
      End excliding
      4.19.0

      Configuration 2

      cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*

      cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*

      cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*

      Configuration 3

      cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*