An issue was discovered in mouse07410 asn1c thru 0.9.29 (2025-03-20) - a fork of vlm asn1c. In UPER (Unaligned Packed Encoding Rules), asn1c-generated decoders fail to enforce INTEGER constraints when the bound is positive and exceeds 32 bits in length, potentially allowing incorrect or malicious input to be processed.
                
            Metrics
Affected Vendors & Products
References
        | Link | Providers | 
|---|---|
| https://github.com/mouse07410/asn1c/issues/222 | 
                     | 
            
History
                    Tue, 26 Aug 2025 14:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Weaknesses | CWE-1284 | |
| Metrics | 
        
        cvssV3_1
         
 
  | 
Sun, 24 Aug 2025 22:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | 
        
        Asn1c Project
         Asn1c Project asn1c  | 
|
| Vendors & Products | 
        
        Asn1c Project
         Asn1c Project asn1c  | 
Fri, 22 Aug 2025 16:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | An issue was discovered in mouse07410 asn1c thru 0.9.29 (2025-03-20) - a fork of vlm asn1c. In UPER (Unaligned Packed Encoding Rules), asn1c-generated decoders fail to enforce INTEGER constraints when the bound is positive and exceeds 32 bits in length, potentially allowing incorrect or malicious input to be processed. | |
| References | 
         | 
Status: PUBLISHED
Assigner: mitre
Published: 2025-08-22T00:00:00.000Z
Updated: 2025-08-26T14:07:57.473Z
Reserved: 2025-08-13T00:00:00.000Z
Link: CVE-2025-55398
Updated: 2025-08-26T13:11:54.313Z
Status : Awaiting Analysis
Published: 2025-08-22T17:15:32.570
Modified: 2025-08-26T14:15:41.030
Link: CVE-2025-55398
No data.
ReportizFlow