CyberRota Analysis
AI-GeneratedThe pyasn1 library for Python is vulnerable to a denial-of-service condition due to improper handling of the univ.Real type, which can lead to excessive CPU and memory consumption when decoding untrusted ASN.1 data. This vulnerability can cause applications to hang during operations like printing or comparing decoded objects. Organizations using pyasn1 versions prior to 0.6.4 should prioritize upgrading to the latest version to mitigate this risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the univ.Real type converted its mantissa, base, and exponent value to a Python float using exact big-integer exponentiation. A BER, CER, or DER encoded REAL value only a few bytes long can carry a very large exponent, causing float conversion through prettyPrint(), str(), comparison, arithmetic, int(), or an explicit float() call to consume excessive CPU and memory and hang applications that decode untrusted ASN.1 data and then print, log, or compare decoded objects. This issue is fixed in version 0.6.4.
Related CVEs
Other vulnerabilities affecting the same vendor(s)