UBUNTU-CVE-2024-12133

Source
https://ubuntu.com/security/CVE-2024-12133
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-12133.json
JSON Data
https://api.test.osv.dev/v1/vulns/UBUNTU-CVE-2024-12133
Related
Published
2025-02-10T16:15:00Z
Modified
2025-02-21T08:46:55Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L CVSS Calculator
Summary
[none]
Details

A flaw in libtasn1 causes inefficient handling of specific certificate data. When processing a large number of elements in a certificate, libtasn1 takes much longer than expected, which can slow down or even crash the system. This flaw allows an attacker to send a specially crafted certificate, causing a denial of service attack.

References

Affected packages

Ubuntu:Pro:14.04:LTS / libtasn1-6

Package

Name
libtasn1-6
Purl
pkg:deb/ubuntu/libtasn1-6@3.4-3ubuntu0.6?arch=source&distro=esm-infra-legacy/trusty

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3.*

3.3-2
3.4-2
3.4-3
3.4-3ubuntu0.1
3.4-3ubuntu0.2
3.4-3ubuntu0.3
3.4-3ubuntu0.4
3.4-3ubuntu0.5
3.4-3ubuntu0.6

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:Pro:16.04:LTS / libtasn1-6

Package

Name
libtasn1-6
Purl
pkg:deb/ubuntu/libtasn1-6@4.7-3ubuntu0.16.04.3+esm3?arch=source&distro=esm-infra/xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

4.*

4.5-2
4.7-2
4.7-3
4.7-3ubuntu0.16.04.1
4.7-3ubuntu0.16.04.2
4.7-3ubuntu0.16.04.3
4.7-3ubuntu0.16.04.3+esm2
4.7-3ubuntu0.16.04.3+esm3

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:Pro:18.04:LTS / libtasn1-6

Package

Name
libtasn1-6
Purl
pkg:deb/ubuntu/libtasn1-6@4.13-2?arch=source&distro=esm-infra/bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

4.*

4.12-2.1
4.12-3
4.13-2

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:20.04:LTS / libtasn1-6

Package

Name
libtasn1-6
Purl
pkg:deb/ubuntu/libtasn1-6@4.16.0-2ubuntu0.1?arch=source&distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.16.0-2ubuntu0.1

Affected versions

4.*

4.14-3
4.15.0-2
4.16.0-2

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "binary_version": "4.16.0-2ubuntu0.1",
            "binary_name": "libtasn1-6"
        },
        {
            "binary_version": "4.16.0-2ubuntu0.1",
            "binary_name": "libtasn1-6-dbgsym"
        },
        {
            "binary_version": "4.16.0-2ubuntu0.1",
            "binary_name": "libtasn1-6-dev"
        },
        {
            "binary_version": "4.16.0-2ubuntu0.1",
            "binary_name": "libtasn1-bin"
        },
        {
            "binary_version": "4.16.0-2ubuntu0.1",
            "binary_name": "libtasn1-bin-dbgsym"
        },
        {
            "binary_version": "4.16.0-2ubuntu0.1",
            "binary_name": "libtasn1-doc"
        }
    ]
}

Ubuntu:22.04:LTS / libtasn1-6

Package

Name
libtasn1-6
Purl
pkg:deb/ubuntu/libtasn1-6@4.18.0-4ubuntu0.1?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.18.0-4ubuntu0.1

Affected versions

4.*

4.16.0-2
4.16.0-2build1
4.17.0-2
4.18.0-3
4.18.0-4
4.18.0-4build1

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "binary_version": "4.18.0-4ubuntu0.1",
            "binary_name": "libtasn1-6"
        },
        {
            "binary_version": "4.18.0-4ubuntu0.1",
            "binary_name": "libtasn1-6-dbgsym"
        },
        {
            "binary_version": "4.18.0-4ubuntu0.1",
            "binary_name": "libtasn1-6-dev"
        },
        {
            "binary_version": "4.18.0-4ubuntu0.1",
            "binary_name": "libtasn1-bin"
        },
        {
            "binary_version": "4.18.0-4ubuntu0.1",
            "binary_name": "libtasn1-bin-dbgsym"
        },
        {
            "binary_version": "4.18.0-4ubuntu0.1",
            "binary_name": "libtasn1-doc"
        }
    ]
}

Ubuntu:24.10 / libtasn1-6

Package

Name
libtasn1-6
Purl
pkg:deb/ubuntu/libtasn1-6@4.19.0-3ubuntu0.24.10.1?arch=source&distro=oracular

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.19.0-3ubuntu0.24.10.1

Affected versions

4.*

4.19.0-3build1

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "binary_version": "4.19.0-3ubuntu0.24.10.1",
            "binary_name": "libtasn1-6"
        },
        {
            "binary_version": "4.19.0-3ubuntu0.24.10.1",
            "binary_name": "libtasn1-6-dbgsym"
        },
        {
            "binary_version": "4.19.0-3ubuntu0.24.10.1",
            "binary_name": "libtasn1-6-dev"
        },
        {
            "binary_version": "4.19.0-3ubuntu0.24.10.1",
            "binary_name": "libtasn1-bin"
        },
        {
            "binary_version": "4.19.0-3ubuntu0.24.10.1",
            "binary_name": "libtasn1-bin-dbgsym"
        },
        {
            "binary_version": "4.19.0-3ubuntu0.24.10.1",
            "binary_name": "libtasn1-doc"
        }
    ]
}

Ubuntu:24.04:LTS / libtasn1-6

Package

Name
libtasn1-6
Purl
pkg:deb/ubuntu/libtasn1-6@4.19.0-3ubuntu0.24.04.1?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.19.0-3ubuntu0.24.04.1

Affected versions

4.*

4.19.0-3
4.19.0-3build1

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "binary_version": "4.19.0-3ubuntu0.24.04.1",
            "binary_name": "libtasn1-6"
        },
        {
            "binary_version": "4.19.0-3ubuntu0.24.04.1",
            "binary_name": "libtasn1-6-dbgsym"
        },
        {
            "binary_version": "4.19.0-3ubuntu0.24.04.1",
            "binary_name": "libtasn1-6-dev"
        },
        {
            "binary_version": "4.19.0-3ubuntu0.24.04.1",
            "binary_name": "libtasn1-bin"
        },
        {
            "binary_version": "4.19.0-3ubuntu0.24.04.1",
            "binary_name": "libtasn1-bin-dbgsym"
        },
        {
            "binary_version": "4.19.0-3ubuntu0.24.04.1",
            "binary_name": "libtasn1-doc"
        }
    ]
}