{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3agnulibtasn1/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:gnu:libtasn1:*:*:*:*:*:*:*:*","cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":4.3,"id":"CVE-2024-11111"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["libtasn1 (\u003c 131.0.6778.69)"],"_cs_severities":["low"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["GNU"],"content_html":"\u003cp\u003eA vulnerability identified in the libtasn1 library, a C library used for Abstract Syntax Notation One (ASN.1) structure management, may be exploited by a remote, anonymous attacker to trigger a Denial of Service (DoS) condition. The flaw affects the processing of ASN.1 data, where specifically crafted inputs can cause the library to enter an unstable state, leading to application crashes or service disruptions for dependent services. Because libtasn1 is widely utilized by various software products for security and data parsing tasks, this vulnerability poses a risk to system availability. Defenders should monitor for unexpected application crashes or service restarts in processes linked to libtasn1.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in a Denial of Service, causing application instability or service outages for systems relying on the libtasn1 library. This can degrade availability for critical infrastructure components that process network or security protocol data.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security operations and IT teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eInventory systems and applications that utilize libtasn1 to identify exposure to CVE-2024-11111.\u003c/li\u003e\n\u003cli\u003eApply patches provided by the GNU project or upstream maintainers as soon as they become available for the distribution or product in use.\u003c/li\u003e\n\u003cli\u003eMonitor logs for repeated service crashes (e.g., core dumps or application-level exit codes) in services that handle external ASN.1 encoded traffic.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-01T12:04:41Z","date_published":"2026-09-01T12:04:41Z","id":"https://feed.craftedsignal.io/briefs/2026-09-libtasn1-dos/","summary":"A vulnerability in the libtasn1 library tracked as CVE-2024-11111 allows a remote, anonymous attacker to cause a Denial of Service condition, potentially impacting applications that rely on the library for ASN.1 structure processing.","title":"Denial of Service Vulnerability in libtasn1","url":"https://feed.craftedsignal.io/briefs/2026-09-libtasn1-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:gnu:libtasn1:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}