CVE-2019-10013
03.12.2019, 20:15
The asn1_signature function in asn1.c in Cameron Hamilton-Rich axTLS through 2.1.5 has a Buffer Overflow that allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted certificate in the TLS certificate handshake message, because the result of get_asn1_length() is not checked for a minimum or maximum size.
Vendor | Product | Version |
---|---|---|
axtls_project | axtls | 𝑥 ≤ 2.1.5 |
𝑥
= Vulnerable software versions

Ubuntu Releases
References