Opened 6 weeks ago
Closed 6 weeks ago
#21032 closed enhancement (fixed)
libtasn1-4.20.0
Reported by: | Douglas R. Reno | Owned by: | Douglas R. Reno |
---|---|---|---|
Priority: | elevated | Milestone: | 12.3 |
Component: | BOOK | Version: | git |
Severity: | normal | Keywords: | |
Cc: |
Description ¶
New minor version
NEWS * Noteworthy changes in release 4.20.0 (2025-02-01) [stable] - The release tarball is now reproducible. - We publish a minimal source-only tarball generated by 'git archive'. - Update gnulib files and various build/maintenance fixes. - Fix CVE-2024-12133: Potential DoS in handling of numerous SEQUENCE OF or SET OF elements
There isn't a rating for CVE-2024-12133 yet so we will assume High for the security advisory, and adjust it later if necessary
Change History (3)
comment:1 by , 6 weeks ago
Owner: | changed from | to
---|---|
Status: | new → assigned |
comment:2 by , 6 weeks ago
comment:3 by , 6 weeks ago
Resolution: | → fixed |
---|---|
Status: | assigned → closed |
Fixed at d3677351d840b5fe15d89f19e8b984d1142a1f6d
SA-12.2-077 issued
Note:
See TracTickets
for help on using tickets.
More details have been released about this vulnerability at https://gitlab.com/gnutls/libtasn1/-/blob/master/doc/security/CVE-2024-12133.md?ref_type=heads
Here's a slightly cleaned up version: