PT-2012-1139 · Gnu+3 · Gnutls+4

Matthew Hall

·

Published

2012-03-26

·

Updated

2024-06-15

·

CVE-2012-1569

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions GNU Libtasn1 versions prior to 2.12 GnuTLS versions prior to 3.0.16
Description The issue arises from the improper handling of certain large length values by the asn1 get length der function in GNU Libtasn1. This can be exploited by remote attackers to cause a denial of service, resulting in heap memory corruption and application crash, or possibly have other unspecified impacts through a crafted ASN.1 structure.
Recommendations For GNU Libtasn1 versions prior to 2.12, update to version 2.12 or later to resolve the issue. For GnuTLS versions prior to 3.0.16, update to version 3.0.16 or later to resolve the issue. As a temporary workaround, consider restricting access to the asn1 get length der function until a patch is available.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-09666
CESA-2012_0427
CVE-2012-1569
DSA-2440-1
OPENSUSE-SU-2024:10105-1
RHSA-2012:0427
RHSA-2012:0428
RHSA-2012:0531
RHSA-2012_0427
RHSA-2012_0428

Affected Products

Centos
Gnu Libtasn1
Gnutls
Red Hat
Suse