CVE-2024-12133

Publication date 10 February 2025

Last updated 21 February 2025


Ubuntu priority

Cvss 3 Severity Score

5.3 · Medium

Score breakdown

A flaw in libtasn1 causes inefficient handling of specific certificate data. When processing a large number of elements in a certificate, libtasn1 takes much longer than expected, which can slow down or even crash the system. This flaw allows an attacker to send a specially crafted certificate, causing a denial of service attack.

Status

Package Ubuntu Release Status
libtasn1-6 24.10 oracular
Fixed 4.19.0-3ubuntu0.24.10.1
24.04 LTS noble
Fixed 4.19.0-3ubuntu0.24.04.1
22.04 LTS jammy
Fixed 4.18.0-4ubuntu0.1
20.04 LTS focal
Fixed 4.16.0-2ubuntu0.1
18.04 LTS bionic
Needs evaluation
16.04 LTS xenial
Needs evaluation

Severity score breakdown

Parameter Value
Base score 5.3 · Medium
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Scope Unchanged
Confidentiality None
Integrity impact None
Availability impact Low
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

References

Related Ubuntu Security Notices (USN)

    • USN-7275-1
    • Libtasn1 vulnerability
    • 18 February 2025
    • USN-7275-2
    • Libtasn1 vulnerability
    • 20 February 2025

Other references