REDHAT-BUG-2430472: High severity pypi/pyasn1 vulnerability
pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.2, a Denial-of-Service issue has been found that leads to memory exhaustion from malformed RELATIVE-OID with excessive continuation octets. This vulnerability is fixed in 0.6.2.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pyasn1to a version that resolves this vulnerability.Fixed in 0.6.2
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2430472?
The severity of REDHAT-BUG-2430472 is classified as a Denial-of-Service vulnerability due to memory exhaustion from malformed RELATIVE-OID.
How do I fix REDHAT-BUG-2430472?
To fix REDHAT-BUG-2430472, upgrade pyasn1 to version 0.6.2 or later.
What versions of pyasn1 are affected by REDHAT-BUG-2430472?
Versions of pyasn1 prior to 0.6.2 are affected by REDHAT-BUG-2430472.
What type of vulnerability is REDHAT-BUG-2430472?
REDHAT-BUG-2430472 is a Denial-of-Service vulnerability.
Is a patch available for REDHAT-BUG-2430472?
Yes, a patch is available in pyasn1 version 0.6.2, which addresses REDHAT-BUG-2430472.