{"id":"CVE-2024-12133","title":"A flaw in libtasn1 causes inefficient handling of specific certificate data","summary":"A flaw in libtasn1 causes inefficient handling of specific certificate data. When processing a large number of elements in a certificate, libtasn1 takes much longer than expected, which can slow down or even crash the system. This flaw a…","severity":"medium","cvss":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","cwe":["CWE-407"],"published":"2025-02-10","updated":"2026-06-29","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2024-12133","references":[{"url":"https://access.redhat.com/errata/RHSA-2025:17347","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:4049","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:7077","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:8021","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:8385","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:30849","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:30850","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/security/cve/CVE-2024-12133","label":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2344611","label":"secalert@redhat.com"},{"url":"https://gitlab.com/gnutls/libtasn1/-/blob/master/doc/security/CVE-2024-12133.md","label":"secalert@redhat.com"},{"url":"https://gitlab.com/gnutls/libtasn1/-/issues/52","label":"secalert@redhat.com"},{"url":"http://www.openwall.com/lists/oss-security/2025/02/06/6","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.debian.org/debian-lts-announce/2025/02/msg00025.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.netapp.com/advisory/ntap-20250523-0003/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://cert-portal.siemens.com/productcert/html/ssa-082556.html","label":"0b142b55-0307-4c5a-b3c9-f314f3fb7c5e"},{"url":"https://cert-portal.siemens.com/productcert/html/ssa-202008.html","label":"0b142b55-0307-4c5a-b3c9-f314f3fb7c5e"}],"tags":["nvd"],"epss":0.0111,"epssPercentile":0.64446,"ingestedAt":"2026-06-26T16:43:13.407Z","slug":"CVE-2024-12133","body":"## Overview\n\nA flaw in libtasn1 causes inefficient handling of specific certificate data. When processing a large number of elements in a certificate, libtasn1 takes much longer than expected, which can slow down or even crash the system. This flaw allows an attacker to send a specially crafted certificate, causing a denial of service attack.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":29,"depthScoreParts":{"impact":29.2,"likelihood":0.2,"exploitation":0,"ransomware":0},"changes":[]}