PT-2012-1139 · Gnu+3 · Gnutls+4

Matthew Hall

·

Publicado

2012-03-26

·

Atualizado

2024-06-15

·

CVE-2012-1569

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions GNU Libtasn1 versions prior to 2.12 GnuTLS versions prior to 3.0.16
Description The issue arises from the improper handling of certain large length values by the asn1 get length der function in GNU Libtasn1. This can be exploited by remote attackers to cause a denial of service, resulting in heap memory corruption and application crash, or possibly have other unspecified impacts through a crafted ASN.1 structure.
Recommendations For GNU Libtasn1 versions prior to 2.12, update to version 2.12 or later to resolve the issue. For GnuTLS versions prior to 3.0.16, update to version 3.0.16 or later to resolve the issue. As a temporary workaround, consider restricting access to the asn1 get length der function until a patch is available.

Exploit

Correção

DoS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-09666
CESA-2012_0427
CVE-2012-1569
DSA-2440-1
OPENSUSE-SU-2024:10105-1
RHSA-2012:0427
RHSA-2012:0428
RHSA-2012:0531
RHSA-2012_0427
RHSA-2012_0428

Produtos afetados

Centos
Gnu Libtasn1
Gnutls
Red Hat
Suse