CVE Vulnerabilities

CVE-2013-7488

Loop with Unreachable Exit Condition ('Infinite Loop')

Published: Apr 07, 2020 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
7.5 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
LOW

perl-Convert-ASN1 (aka the Convert::ASN1 module for Perl) through 0.27 allows remote attackers to cause an infinite loop via unexpected input.

Weakness

The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

Affected Software

Name Vendor Start Version End Version
Convert::asn1 Convert::asn1_project * 0.27 (including)
Red Hat Enterprise Linux 8 RedHat perl-Convert-ASN1-0:0.27-18.el8 *
Libconvert-asn1-perl Ubuntu bionic *
Libconvert-asn1-perl Ubuntu eoan *
Libconvert-asn1-perl Ubuntu esm-infra/bionic *
Libconvert-asn1-perl Ubuntu esm-infra/xenial *
Libconvert-asn1-perl Ubuntu focal *
Libconvert-asn1-perl Ubuntu groovy *
Libconvert-asn1-perl Ubuntu hirsute *
Libconvert-asn1-perl Ubuntu impish *
Libconvert-asn1-perl Ubuntu kinetic *
Libconvert-asn1-perl Ubuntu lunar *
Libconvert-asn1-perl Ubuntu mantic *
Libconvert-asn1-perl Ubuntu trusty *
Libconvert-asn1-perl Ubuntu upstream *
Libconvert-asn1-perl Ubuntu xenial *

References