CVE-2023-39914CWE-232CWE-240

BER/CER/DER decoder panics on invalid input

High · published September 13, 2023

CVSS v3.1
7.5
EPSS
1%
Percentile
45.9
In the wild
Unconfirmed
What it is

NLnet Labs' bcder library up to and including version 0.7.2 panics while decoding certain invalid input data rather than rejecting the data with an error. This can affect both the actual decoding stage as well as accessing content of types that utilized delayed decoding.

The record
Technical detail
CVSS v3.1
7.5 · HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS v4.0
Not supplied
EPSS
0.00587 · 45.9th percentile
Weaknesses
CWE-232 · Improper Handling of Undefined Values; CWE-240 · Improper Handling of Inconsistent Structural Elements
Published
2023-09-13T14:17Z
EPSS history
Timeline
  • 13 SEP 14:17Z
    BER/CER/DER decoder panics on invalid input
    cvelistv5