CVE-2013-7488
Rocky Linux vulnerability analysis and mitigation

Overview

CVE-2013-7488 affects perl-Convert-ASN1 (also known as the Convert::ASN1 module for Perl) through version 0.27. The vulnerability allows remote attackers to cause an infinite loop via unexpected input (NVD, MITRE).

Technical details

The vulnerability has a CVSS v3.1 Base Score of 7.5 (HIGH) with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H. The issue is classified as CWE-835 (Loop with Unreachable Exit Condition - 'Infinite Loop'). The vulnerability specifically occurs in the decoding process where unsafe input can trigger an infinite loop in the _decode.pm file, particularly in two do loops on lines 636 and 690 (GitHub Issue).

Impact

When exploited, this vulnerability can cause a denial of service condition through an infinite loop that continuously spews warnings. This can affect applications using Convert::ASN1 for ASN.1 data structure encoding and decoding, particularly impacting availability. The issue can also manifest when using Convert::PEM with incorrect passwords (GitHub Issue).

Exploitability

The vulnerability is remotely exploitable and requires no special privileges or user interaction. The attack complexity is rated as low, making it relatively straightforward to exploit using specially crafted input (NVD).

Mitigation and workarounds

A fix has been implemented by adding position checks to the two do loops in _decode.pm. The fix ensures that the position doesn't exceed the end of the input during decoding. Various distributions have released patches, including Fedora which addressed the issue in versions 0.27-21.fc33 and 0.27-19.fc32 (Fedora Update).

Additional resources


SourceThis report was generated using AI

Related Rocky Linux vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64561HIGH8.8
  • Linux Kernel logoLinux Kernel
  • kernel-debug-devel-matched
NoYesAug 04, 2026
CVE-2026-7867HIGH7.8
  • Rocky Linux logoRocky Linux
  • udisks2-debugsource
NoYesAug 06, 2026
CVE-2026-5056HIGH7.8
  • Rocky Linux logoRocky Linux
  • mingw32-gstreamer1-plugins-good-debuginfo
NoYesJul 29, 2026
CVE-2026-18649HIGH7.5
  • Rocky Linux logoRocky Linux
  • gstreamer1-plugins-good-gtk
NoYesAug 06, 2026
CVE-2026-69152HIGH7.5
  • JavaScript logoJavaScript
  • grafana-elasticsearch
NoYesAug 03, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management