First published: Wed Sep 13 2023(Updated: )
NLnet Labs' bcder library up to and including version 0.7.2 panics while decoding certain invalid input data rather than rejecting the data with an error. This can affect both the actual decoding stage as well as accessing content of types that utilized delayed decoding.
Credit: sep@nlnetlabs.nl sep@nlnetlabs.nl sep@nlnetlabs.nl
Affected Software | Affected Version | How to fix |
---|---|---|
rust/bcder | <0.7.3 | 0.7.3 |
Nlnetlabs Bcder | <0.7.3 |
This issue is fixed in 0.7.3 and all later versions.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-39914 is a vulnerability in NLnet Labs' bcder library up to and including version 0.7.2 that can cause the library to panic while decoding certain invalid input data.
CVE-2023-39914 has a severity rating of 7.5 (high).
CVE-2023-39914 can affect both the actual decoding stage and accessing content of types that utilize delayed decoding.
If you are using NLnet Labs' bcder library version 0.7.2 or earlier, your system may be affected by CVE-2023-39914.
To fix CVE-2023-39914, update your bcder library to version 0.7.3 or later.