PT-2014-9102 · Gnu+5 · Libtasn1+8

Publicado

1970-01-01

·

Atualizado

2024-06-15

·

CVE-2014-3469

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions libtasn1 versions prior to 3.6 libtasn1-devel versions 2.3 through 3.3 libtasn1-debuginfo versions 2.3 through 3.3 libtasn1-tools versions 2.3 through 3.3
Description Multiple vulnerabilities in the libtasn1 package can lead to disruption of confidentiality, integrity, and availability of protected information. The vulnerabilities can be exploited remotely, allowing context-dependent attackers to cause a denial of service (NULL pointer dereference and crash) via a NULL value in an ivalue argument. The asn1 read value type and asn1 read value functions are specifically affected.
Recommendations For libtasn1 versions prior to 3.6, update to version 3.6 or later to resolve the issue. For libtasn1-devel versions 2.3 through 3.3, update to a version outside of this range to mitigate the risk. For libtasn1-debuginfo versions 2.3 through 3.3, update to a version outside of this range to mitigate the risk. For libtasn1-tools versions 2.3 through 3.3, update to a version outside of this range to mitigate the risk. As a temporary workaround, consider restricting access to the vulnerable functions asn1 read value type and asn1 read value until a patch is available.

Exploit

Correção

DoS

NULL Pointer Dereference

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2014-2314
ALT-PU-2017-1026
BDU:2015-04302
BDU:2015-04303
BDU:2015-04304
BDU:2015-04305
BDU:2015-06328
BDU:2015-06329
BDU:2015-06330
BDU:2015-06331
BDU:2015-06332
BDU:2015-06333
BDU:2015-06334
BDU:2015-06335
BDU:2015-09787
CESA-2014_0596
CVE-2014-3469
DLA-77-1
DSA-3056-1
MGASA-2014-0247
OPENSUSE-SU-2024:10414-1
RHSA-2014:0594
RHSA-2014:0596
RHSA-2014:0687
RHSA-2014:0815
RHSA-2014_0594
RHSA-2014_0596
RHSA-2014_0687
SUSE-SU-2015:0901-1
USN-2294-1

Produtos afetados

Alt Linux
Centos
Red Hat
Suse
Ubuntu
Libtasn1
Libtasn1-Debuginfo
Libtasn1-Devel
Libtasn1-Tools