PT-2014-9101 · Gnu+5 · Libtasn1+5

Published

1970-01-01

·

Updated

2024-06-15

·

CVE-2014-3468

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions libtasn1 versions prior to 3.6 libtasn1-devel versions 2.3 through 3.3 libtasn1-debuginfo versions 2.3 through 3.3 libtasn1-tools versions 2.3 through 3.3
Description The issue is related to multiple vulnerabilities in the libtasn1 package, which can lead to disruption of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. The asn1 get bit der function in GNU Libtasn1 before version 3.6 does not properly report an error when a negative bit length is identified, allowing context-dependent attackers to cause out-of-bounds access via crafted ASN.1 data.
Recommendations For libtasn1 versions prior to 3.6, update to version 3.6 or later to resolve the issue. For libtasn1-devel versions 2.3 through 3.3, update to version 3.6 or later to resolve the issue. For libtasn1-debuginfo versions 2.3 through 3.3, update to version 3.6 or later to resolve the issue. For libtasn1-tools versions 2.3 through 3.3, update to version 3.6 or later to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable functions until a patch is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2014-2314
ALT-PU-2017-1026
BDU:2015-04302
BDU:2015-04303
BDU:2015-04304
BDU:2015-04305
BDU:2015-06328
BDU:2015-06329
BDU:2015-06330
BDU:2015-06331
BDU:2015-06332
BDU:2015-06333
BDU:2015-06334
BDU:2015-06335
BDU:2015-09787
CESA-2014_0596
CVE-2014-3468
DLA-77-1
DSA-3056-1
MGASA-2014-0247
OPENSUSE-SU-2024:10414-1
RHSA-2014:0594
RHSA-2014:0596
RHSA-2014:0687
RHSA-2014:0815
RHSA-2014_0594
RHSA-2014_0596
RHSA-2014_0687
SUSE-SU-2015:0901-1
USN-2294-1

Affected Products

Alt Linux
Centos
Red Hat
Suse
Ubuntu
Libtasn1