CVE-2023-39914CWE-232CWE-240
BER/CER/DER decoder panics on invalid input
High · published September 13, 2023
What it is
NLnet Labs' bcder library up to and including version 0.7.2 panics while decoding certain invalid input data rather than rejecting the data with an error. This can affect both the actual decoding stage as well as accessing content of types that utilized delayed decoding.
The record
Technical detail
- CVSS v3.1
- 7.5 · HIGH
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- CVSS v4.0
- Not supplied
- EPSS
- 0.00587 · 45.9th percentile
- Weaknesses
- CWE-232 · Improper Handling of Undefined Values; CWE-240 · Improper Handling of Inconsistent Structural Elements
- Published
- 2023-09-13T14:17Z
EPSS history
Timeline