CVE-2017-6891: Apache Bookkeeper
High severity, CVSS 8.8. EPSS: 5.6% chance of exploitation in the next 30 days.
Two errors in the "asn1_find_node()" function (lib/parser_aux.c) within GnuTLS libtasn1 version 4.10 can be exploited to cause a stacked-based buffer overflow by tricking a user into processing a specially crafted assignments file via the e.g. asn1Coding utility.
Affected products
- Apache Bookkeeper: version 4.12.1 only
- Debian Debian Linux: version 8.0 only
- GNU LIBTASN1: version 4.10 only
Published 2017-05-22. Last modified 2026-06-17.