CRITICAL 9.1 Microsoft
CVE-2021-46848
GNU Libtasn1 before 4.19.0 has an ETYPE_OK off-by-one array size check that affects asn1_encode_simple_der.
Microsoft Security Update 2022-Oct: GNU Libtasn1 before 4.19.0 has an ETYPE_OK off-by-one array size check that affects asn1_encode_simple_der.
Affected Products
- cm1 libtasn1 4.14-3 on CBL Mariner 1.0
- cbl2 libtasn1 4.19.0-1 on CBL Mariner 2.0
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-46848
- https://nvd.nist.gov/vuln/detail/CVE-2021-46848
This critical severity vulnerability with a CVSS score of 9.1 was published on 2022-10-11 via Microsoft. Affected: cm1 libtasn1 4.14-3 on CBL Mariner 1.0, cbl2 libtasn1 4.19.0-1 on CBL Mariner 2.0.
Risk Timeline
CVE Disclosed2022-10-11 · 1422 days ago
Remediation Resources
Official Advisory
msrc.microsoft.com/update-guide/vulnerability/CVE-2021-46848NVD / MITRE
nvd.nist.gov/vuln/detail/CVE-2021-46848Related Vulnerabilities
| CVE | Title | Severity | CVSS |
|---|---|---|---|
| CVE-2022-37454 | The Keccak XKCP SHA-3 reference implementation before fdc6fef has an integer ove | CRITICAL | 9.8 |
| CVE-2021-33643 | An attacker who submits a crafted tar file with size in header struct being 0 ma | CRITICAL | 9.1 |
| CVE-2022-42719 | A use-after-free in the mac80211 stack when parsing a multi-BSSID element in the | HIGH | 8.8 |
| CVE-2022-1043 | A flaw was found in the Linux kernel’s io_uring implementation. This flaw allows | HIGH | 8.8 |
| CVE-2022-1271 | An arbitrary file write vulnerability was found in GNU gzip's zgrep utility. Whe | HIGH | 8.8 |
| CVE-2022-1552 | A flaw was found in PostgreSQL. There is an issue with incomplete efforts to ope | HIGH | 8.8 |
vulnfeed aggregates 9119 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.