suse · CVE-2017-14033

Quick triage

Priority: medium Published: 2021-05-30 14:01:37 UTC Updated: 2026-04-17 15:56:06 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2017-14033 severity moderate: SUSE including 24 source package names (libruby2_1-2_1-2.1.9-19.3.2, ruby, …), 168 product×package rows across 60 product lines (HPE Helion OpenStack 8, Image SLES12-SP5-Azure-BYOS, … (60 product lines)): Fixed 140, Known Not Affected 23, Will Not Fix 5.

Description:

The decode method in the OpenSSL::ASN1 module in Ruby before 2.2.8, 2.3.x before 2.3.5, and 2.4.x through 2.4.1 allows attackers to cause a denial of service (interpreter crash) via a crafted string.

cvelogic Threat Intelligence