CVE-2021-46848: Critical severity libtasn1 vulnerability
GNU Libtasn1 before 4.19.0 has an ETYPEOK off-by-one array size check that affects asn1encodesimpleder.
Other sources
GNU Libtasn1 could allow a remote attacker to obtain sensitive information, caused by an out-of-bound access flaw in ETYPEOK. By sending a specially-crafted request, an attacker could exploit this vulnerability to obtain sensitive information, or cause a denial of service condition.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-46848?
CVE-2021-46848 is a vulnerability in GNU Libtasn1 before version 4.19.0, which could allow a remote attacker to obtain sensitive information or cause a denial of service.
How can an attacker exploit CVE-2021-46848?
An attacker can exploit CVE-2021-46848 by sending a specially-crafted request to the affected system.
What is the severity of CVE-2021-46848?
CVE-2021-46848 has a severity rating of 9.1 (critical).
Which software versions are affected by CVE-2021-46848?
GNU Libtasn1 versions up to and excluding 4.19.0 are affected, as well as Fedora 35, 36, and 37, Debian Debian Linux 10.0, and IBM Security Verify Access Docker and IBM Security Verify Access up to version 10.0.X.
How can I mitigate CVE-2021-46848?
To mitigate CVE-2021-46848, it is recommended to update to GNU Libtasn1 version 4.19.0 and apply any necessary patches provided by your software vendor.