OSV-2023-1009

See a problem?
Import Source
https://github.com/google/oss-fuzz-vulns/blob/main/vulns/jsign/OSV-2023-1009.yaml
JSON Data
https://api.osv.dev/v1/vulns/OSV-2023-1009
Published
2023-10-13T13:00:25.417249Z
Modified
2023-10-13T13:00:25.417557Z
Summary
Security exception in net.jsign.bouncycastle.asn1.ASN1StreamParser.readVector
Details

OSS-Fuzz report: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=63217

Crash type: Security exception
Crash state:
net.jsign.bouncycastle.asn1.ASN1StreamParser.readVector
net.jsign.bouncycastle.asn1.ASN1StreamParser.loadTaggedIL
net.jsign.bouncycastle.asn1.BERTaggedObjectParser.getLoadedObject
References

Affected packages

OSS-Fuzz / jsign

Package

Name
jsign
Purl
pkg:generic/jsign

Affected ranges

Type
GIT
Repo
https://github.com/ebourg/jsign.git
Events

Ecosystem specific

{
    "severity": "LOW"
}

Database specific

{
    "introduced_range": "65fea7237f17973b08cd65144e85a34d114f2030:8d83bd10f183d39b1955e38bf76c66305eefb3ac"
}