
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2013-7488 affects perl-Convert-ASN1 (also known as the Convert::ASN1 module for Perl) through version 0.27. The vulnerability allows remote attackers to cause an infinite loop via unexpected input (NVD, MITRE).
The vulnerability has a CVSS v3.1 Base Score of 7.5 (HIGH) with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H. The issue is classified as CWE-835 (Loop with Unreachable Exit Condition - 'Infinite Loop'). The vulnerability specifically occurs in the decoding process where unsafe input can trigger an infinite loop in the _decode.pm file, particularly in two do loops on lines 636 and 690 (GitHub Issue).
When exploited, this vulnerability can cause a denial of service condition through an infinite loop that continuously spews warnings. This can affect applications using Convert::ASN1 for ASN.1 data structure encoding and decoding, particularly impacting availability. The issue can also manifest when using Convert::PEM with incorrect passwords (GitHub Issue).
The vulnerability is remotely exploitable and requires no special privileges or user interaction. The attack complexity is rated as low, making it relatively straightforward to exploit using specially crafted input (NVD).
A fix has been implemented by adding position checks to the two do loops in _decode.pm. The fix ensures that the position doesn't exceed the end of the input during decoding. Various distributions have released patches, including Fedora which addressed the issue in versions 0.27-21.fc33 and 0.27-19.fc32 (Fedora Update).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."