CVE-2023-39914
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
13/09/2023
Last modified:
11/09/2024
Description
NLnet Labs' bcder library up to and including version 0.7.2 panics while decoding certain invalid input data rather than rejecting the data with an error. This can affect both the actual decoding stage as well as accessing content of types that utilized delayed decoding.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:nlnetlabs:bcder:*:*:*:*:*:*:*:* | 0.7.3 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



