File _patchinfo of Package patchinfo.11138

<patchinfo incident="11138">
  <issue tracker="bnc" id="1105435">VUL-0: CVE-2018-1000654: libtasn1: contains a DoS, specifically CPU usage will reach 100% when running asn1Paser</issue>
  <issue tracker="bnc" id="1040621">VUL-0: CVE-2017-6891: gnutls,libtasn1: asn1_find_node() based stackoverflow</issue>
  <issue tracker="bnc" id="1204690">VUL-0: CVE-2021-46848: libtasn1: off-by-one array size check that affects asn1_encode_simple_der</issue>
  <issue tracker="cve" id="2021-46848"/>
  <issue tracker="cve" id="2018-1000654"/>
  <issue tracker="cve" id="2017-6891"/>
  <packager>mgorse</packager>
  <rating>critical</rating>
  <category>security</category>
  <summary>Security update for libtasn1</summary>
  <description>This update for libtasn1 fixes the following issues:

Security issue fixed:

- CVE-2018-1000654: Fixed a denial of service in the asn1 parser (bsc#1105435).
- CVE-2017-6891: Added safety check to fix a stack overflow issue (bsc#1040621).
- CVE-2021-46848: Fixed off-by-one array size check that affects asn1_encode_simple_der (bsc#1204690)
</description>
</patchinfo>
openSUSE Build Service is sponsored by