BER/CER/DER decoder panics on invalid input
Vulnerability Description
NLnet Labs' bcder library up to and including version 0.7.2 panics while decoding certain invalid input data rather than rejecting the data with an error. This can affect both the actual decoding stage as well as accessing content of types that utilized delayed decoding.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-39914
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Haya Shulman
- Donika Mirdita
- Niklas Vogel
More from NLnet Labs
View All →Affected Vendor
NLnet Labs
View all reports →Affected Software
Timeline
CVSS Vectors
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.