CVE-2017-6891: Apache Bookkeeper

High severity, CVSS 8.8. EPSS: 5.6% chance of exploitation in the next 30 days.

Two errors in the "asn1_find_node()" function (lib/parser_aux.c) within GnuTLS libtasn1 version 4.10 can be exploited to cause a stacked-based buffer overflow by tricking a user into processing a specially crafted assignments file via the e.g. asn1Coding utility.

Affected products

  • Apache Bookkeeper: version 4.12.1 only
  • Debian Debian Linux: version 8.0 only
  • GNU LIBTASN1: version 4.10 only

Published 2017-05-22. Last modified 2026-06-17.