CVE-2017-10790: Null Pointer Dereference
Last updated 25 August 2025
Other sources
The asn1checkidentifier function in GNU Libtasn1 through 4.12 causes a NULL pointer dereference and crash when reading crafted input that triggers assignment of a NULL value within an asn1node structure. It may lead to a remote denial of service attack.
— Launchpad
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-10790?
CVE-2017-10790 is a vulnerability in GNU Libtasn1 that causes a NULL pointer dereference and crash when reading crafted input, leading to a remote denial of service attack.
What is the severity of CVE-2017-10790?
CVE-2017-10790 has a severity rating of 7.5, which is considered high.
How does CVE-2017-10790 affect the software?
CVE-2017-10790 affects GNU Libtasn1 versions 4.12-2.1 and 4.10-1.1+deb9u1, causing a NULL pointer dereference and crash when reading crafted input.
How can I fix CVE-2017-10790?
To fix CVE-2017-10790, update to version 4.13-3 or later for Debian, or version 4.19.0-2 or later for Ubuntu.
Where can I find more information about CVE-2017-10790?
More information about CVE-2017-10790 can be found at the following references: [1] [2] [3]