File _patchinfo of Package patchinfo.11138
<patchinfo incident="11138">
<issue tracker="bnc" id="1105435">VUL-0: CVE-2018-1000654: libtasn1: contains a DoS, specifically CPU usage will reach 100% when running asn1Paser</issue>
<issue tracker="bnc" id="1040621">VUL-0: CVE-2017-6891: gnutls,libtasn1: asn1_find_node() based stackoverflow</issue>
<issue tracker="bnc" id="1204690">VUL-0: CVE-2021-46848: libtasn1: off-by-one array size check that affects asn1_encode_simple_der</issue>
<issue tracker="cve" id="2021-46848"/>
<issue tracker="cve" id="2018-1000654"/>
<issue tracker="cve" id="2017-6891"/>
<packager>mgorse</packager>
<rating>critical</rating>
<category>security</category>
<summary>Security update for libtasn1</summary>
<description>This update for libtasn1 fixes the following issues:
Security issue fixed:
- CVE-2018-1000654: Fixed a denial of service in the asn1 parser (bsc#1105435).
- CVE-2017-6891: Added safety check to fix a stack overflow issue (bsc#1040621).
- CVE-2021-46848: Fixed off-by-one array size check that affects asn1_encode_simple_der (bsc#1204690)
</description>
</patchinfo>