Crypto Foundation Cracked: One-Byte Overflow in GNU libtasn1 (CVE-2025-13151)
ID: 8f13b3b7-6239-5338-8370-1523d9f40d01
STIX ID: report--8f13b3b7-6239-5338-8370-1523d9f40d01
Feed Name: securityonline.info
A stack-based buffer overflow (CVE-2025-13151, CVSS 7.5) was disclosed in GNU libtasn1’s asn1_expand_octet_string due to unsafe string concatenation (strcpy/strcat) that can overflow a stack buffer by one byte; while this can cause memory corruption during certificate parsing or signature verification, exploitation requires malformed ASN.1 input and may be mitigated by modern protections such as stack canaries and _FORTIFY_SOURCE; a patch has been proposed and developers are urged to apply bounded string operations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
