CVE-2024-57765
Mié, 15/01/2025 – 00:15
CVE-2024-57765
CVE-2024-57765
Mié, 15/01/2025 – 00:15
CVE-2024-57765
CVE-2024-57764
Mié, 15/01/2025 – 00:15
CVE-2024-57764
CVE-2024-57763
Mié, 15/01/2025 – 00:15
CVE-2024-57763
CVE-2025-22997
Mié, 15/01/2025 – 00:15
CVE-2025-22997
CVE-2025-22996
Mié, 15/01/2025 – 00:15
CVE-2025-22996
CVE-2025-0343
Mié, 15/01/2025 – 01:15
CVE-2025-0343
Importantly, these constraints are actually required to be true in DER, but that correctness wasn't enforced on the early node parser side so it was incorrect to rely on it later on in decoding, which is what the library did.
These crashes can be triggered when parsing any DER/BER format object. There is no memory-safety issue here: the crash is a graceful one from the Swift runtime. The impact of this is that it can be used as a denial-of-service vector when parsing BER/DER data from unknown sources, e.g. when parsing TLS certificates.
CVE-2024-57482
Mar, 14/01/2025 – 22:15
CVE-2024-57482
CVE-2024-57480
Mar, 14/01/2025 – 22:15
CVE-2024-57480
CVE-2024-57479
Mar, 14/01/2025 – 22:15
CVE-2024-57479
CVE-2024-42911
Mar, 14/01/2025 – 23:15
CVE-2024-42911