Vulnerability Name: | CVE-2021-46848 (CCN-240735) | ||||||||||||||||||||
Assigned: | 2021-02-04 | ||||||||||||||||||||
Published: | 2021-02-04 | ||||||||||||||||||||
Updated: | 2023-01-20 | ||||||||||||||||||||
Summary: | GNU Libtasn1 before 4.19.0 has an ETYPE_OK off-by-one array size check that affects asn1_encode_simple_der. | ||||||||||||||||||||
CVSS v3 Severity: | 9.1 Critical (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H) 8.2 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H/E:P/RL:O/RC:C)
8.2 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H/E:P/RL:O/RC:C)
5.3 Medium (REDHAT Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C)
| ||||||||||||||||||||
CVSS v2 Severity: | 9.4 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:N/A:C)
| ||||||||||||||||||||
Vulnerability Type: | CWE-125 | ||||||||||||||||||||
Vulnerability Consequences: | Obtain Information | ||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2021-46848 Source: XF Type: UNKNOWN gnu-cve202146848-info-disc(240735) Source: CCN Type: Libtasn1 GIT Repository Out-of-bound access in ETYPE_OK Source: CCN Type: IBM Security Bulletin 6857613 (MQ Operator) BM MQ Operator and Queue manager container images are vulnerable to multiple vulnerabilities from libxml2, expat, libtasn1 and systemd Source: CCN Type: IBM Security Bulletin 6967243 (Cloud Pak for Watson AIOps) Multiple Vulnerabilities in CloudPak for Watson AIOPs Source: CCN Type: IBM Security Bulletin 6967291 (Robotic Process Automation for Cloud Pak) Multiple Security Vulnerabilities may affect IBM Robotic Process Automation for Cloud Pak. Source: CCN Type: IBM Security Bulletin 6981853 (Watson Speech Services Cartridge for Cloud Pak for Data) IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data is vulnerable to a security restrictions bypass in GNU Libtasn1 [CVE-2021-46848] Source: CCN Type: IBM Security Bulletin 6986547 (Power HMC) Vulnerability in libtasn1 (CVE-2021-46848) affects Power HMC Source: CCN Type: IBM Security Bulletin 6986569 (MQ Appliance) IBM MQ Appliance is affected by multiple open source vulnerabilities Source: CCN Type: IBM Security Bulletin 6989653 (Security Verify Access) Multiple Security Vulnerabilities have been fixed in IBM Security Verify Access Source: CCN Type: IBM Security Bulletin 7001867 (Cloud Pak for Security) IBM Cloud Pak for Security includes components with multiple known vulnerabilities Source: CCN Type: Mend Vulnerability Database CVE-2021-46848 | ||||||||||||||||||||
Vulnerable Configuration: | Configuration RedHat 1: Configuration CCN 1: ![]() | ||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||
| |||||||||||||||||||||
BACK |