PT-2014-9101 · Gnu+5 · Libtasn1+5

Publicado

1970-01-01

·

Atualizado

2024-06-15

·

CVE-2014-3468

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions libtasn1 versions prior to 3.6 libtasn1-devel versions 2.3 through 3.3 libtasn1-debuginfo versions 2.3 through 3.3 libtasn1-tools versions 2.3 through 3.3
Description The issue is related to multiple vulnerabilities in the libtasn1 package, which can lead to disruption of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. The asn1 get bit der function in GNU Libtasn1 before version 3.6 does not properly report an error when a negative bit length is identified, allowing context-dependent attackers to cause out-of-bounds access via crafted ASN.1 data.
Recommendations For libtasn1 versions prior to 3.6, update to version 3.6 or later to resolve the issue. For libtasn1-devel versions 2.3 through 3.3, update to version 3.6 or later to resolve the issue. For libtasn1-debuginfo versions 2.3 through 3.3, update to version 3.6 or later to resolve the issue. For libtasn1-tools versions 2.3 through 3.3, update to version 3.6 or later to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable functions until a patch is available.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2014-2314
ALT-PU-2017-1026
BDU:2015-04302
BDU:2015-04303
BDU:2015-04304
BDU:2015-04305
BDU:2015-06328
BDU:2015-06329
BDU:2015-06330
BDU:2015-06331
BDU:2015-06332
BDU:2015-06333
BDU:2015-06334
BDU:2015-06335
BDU:2015-09787
CESA-2014_0596
CVE-2014-3468
DLA-77-1
DSA-3056-1
MGASA-2014-0247
OPENSUSE-SU-2024:10414-1
RHSA-2014:0594
RHSA-2014:0596
RHSA-2014:0687
RHSA-2014:0815
RHSA-2014_0594
RHSA-2014_0596
RHSA-2014_0687
SUSE-SU-2015:0901-1
USN-2294-1

Produtos afetados

Alt Linux
Centos
Red Hat
Suse
Ubuntu
Libtasn1