CVE-2012-1569 describes a heap memory corruption vulnerability in the asn1_get_length_der function of GNU Libtasn1 before version 2.12, also affecting GnuTLS before 3.0.16. This flaw allows remote attackers to trigger a denial of service (application crash) or potentially other unspecified impacts by providing a specially crafted ASN.1 structure. With a CVSS score of 5.0 (AV:N/AC:L/Au:N/C:N/I:N/A:P), it is a medium-severity vulnerability that can be exploited remotely with low attack complexity, leading to partial availability impact. There is no evidence of active exploitation, no known public exploit code (Metasploit, Nuclei, ExploitDB), and it is not listed in the KEV catalog, though it has received some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 3.0.15CPE matchmatch criteria | cpe:2.3:a:gnu:gnutls:*:*:*:*:*:*:*:* | ||
1.0.16CPE matchmatch criteria | cpe:2.3:a:gnu:gnutls:1.0.16:*:*:*:*:*:*:* | ||
1.0.17CPE matchmatch criteria | cpe:2.3:a:gnu:gnutls:1.0.17:*:*:*:*:*:*:* | ||
1.0.18CPE matchmatch criteria | cpe:2.3:a:gnu:gnutls:1.0.18:*:*:*:*:*:*:* | ||
1.0.19CPE matchmatch criteria | cpe:2.3:a:gnu:gnutls:1.0.19:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.