CVE-2013-7488
Rocky Linux vulnerability analysis and mitigation

Overview

CVE-2013-7488 affects perl-Convert-ASN1 (also known as the Convert::ASN1 module for Perl) through version 0.27. The vulnerability allows remote attackers to cause an infinite loop via unexpected input (NVD, MITRE).

Technical details

The vulnerability has a CVSS v3.1 Base Score of 7.5 (HIGH) with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H. The issue is classified as CWE-835 (Loop with Unreachable Exit Condition - 'Infinite Loop'). The vulnerability specifically occurs in the decoding process where unsafe input can trigger an infinite loop in the _decode.pm file, particularly in two do loops on lines 636 and 690 (GitHub Issue).

Impact

When exploited, this vulnerability can cause a denial of service condition through an infinite loop that continuously spews warnings. This can affect applications using Convert::ASN1 for ASN.1 data structure encoding and decoding, particularly impacting availability. The issue can also manifest when using Convert::PEM with incorrect passwords (GitHub Issue).

Mitigation and workarounds

A fix has been implemented by adding position checks to the two do loops in _decode.pm. The fix ensures that the position doesn't exceed the end of the input during decoding. Various distributions have released patches, including Fedora which addressed the issue in versions 0.27-21.fc33 and 0.27-19.fc32 (Fedora Update).

Additional resources


SourceThis report was generated using AI

Related Rocky Linux vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-13699HIGH7
  • MariaDB ServerMariaDB Server
  • mariadb:10.3::mariadb-common
NoYesDec 23, 2025
CVE-2025-43541MEDIUM4.3
  • Apple SafariApple Safari
  • javascriptcoregtk4.1-debuginfo
NoYesDec 17, 2025
CVE-2025-43536MEDIUM4.3
  • Apple SafariApple Safari
  • javascriptcoregtk6.0-debuginfo
NoYesDec 17, 2025
CVE-2025-43535MEDIUM4.3
  • Apple SafariApple Safari
  • webkit2gtk3-devel
NoYesDec 17, 2025
CVE-2025-61594LOW2.7
  • RubyRuby
  • ruby:3.3::rubygem-mongo-doc
NoYesDec 30, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management