Dismissed
Permalink
CVE-2025-13151
7.5 HIGH
- CVSS version: 3.1
- Attack vector (AV): NETWORK
- Attack complexity (AC): LOW
- Privileges required (PR): NONE
- User interaction (UI): NONE
- Scope (S): UNCHANGED
- Confidentiality impact (C): NONE
- Integrity impact (I): NONE
- Availability impact (A): HIGH
by @tomberek Activity log
- Created automatic suggestion
- @tomberek dismissed
CVE-2025-13151
Stack-based buffer overflow in libtasn1 version: v4.20.0. The function fails to validate the size of input data resulting in a buffer overflow in asn1_expend_octet_string.
References
- Source Code Respoitory
- Proposed Pull Request patch
- Source Code Respoitory
- Proposed Pull Request patch
- http://www.openwall.com/lists/oss-security/2026/01/08/5
- Source Code Respoitory
- Proposed Pull Request patch
- http://www.openwall.com/lists/oss-security/2026/01/08/5
- https://www.kb.cert.org/vuls/id/271649
Affected products
libtasn1
- =<4.20.0