Missing Report of Error Condition Affecting libtasn1 package, versions <0:2.3-6.el6_5
Threat Intelligence
EPSS
0.73% (81st
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-CENTOS6-LIBTASN1-2099383
- published 26 Jul 2021
- disclosed 25 May 2014
How to fix?
Upgrade Centos:6
libtasn1
to version 0:2.3-6.el6_5 or higher.
NVD Description
Note: Versions mentioned in the description apply only to the upstream libtasn1
package and not the libtasn1
package as distributed by Centos
.
See How to fix?
for Centos:6
relevant fixed versions and status.
The asn1_get_bit_der function in GNU Libtasn1 before 3.6 does not properly report an error when a negative bit length is identified, which allows context-dependent attackers to cause out-of-bounds access via crafted ASN.1 data.
References
- http://advisories.mageia.org/MGASA-2014-0247.html
- http://git.savannah.gnu.org/cgit/libtasn1.git/commit/?id=1c3ccb3e040bf13e342ee60bc23b21b97b11923f
- http://linux.oracle.com/errata/ELSA-2014-0594.html
- http://linux.oracle.com/errata/ELSA-2014-0596.html
- https://bugzilla.redhat.com/show_bug.cgi?id=1102323
- http://support.f5.com/kb/en-us/solutions/public/15000/400/sol15423.html
- http://www.novell.com/support/kb/doc.php?id=7015302
- http://www.novell.com/support/kb/doc.php?id=7015303
- https://access.redhat.com/security/cve/CVE-2014-3468
- http://www.debian.org/security/2014/dsa-3056
- http://www.mandriva.com/security/advisories?name=MDVSA-2015:116
- http://lists.gnu.org/archive/html/help-libtasn1/2014-05/msg00006.html
- http://rhn.redhat.com/errata/RHSA-2014-0594.html
- http://rhn.redhat.com/errata/RHSA-2014-0596.html
- http://rhn.redhat.com/errata/RHSA-2014-0687.html
- http://rhn.redhat.com/errata/RHSA-2014-0815.html
- https://access.redhat.com/errata/RHSA-2014:0596
- http://secunia.com/advisories/58591
- http://secunia.com/advisories/58614
- http://secunia.com/advisories/59021
- http://secunia.com/advisories/59057
- http://secunia.com/advisories/59408
- http://secunia.com/advisories/60320
- http://secunia.com/advisories/60415
- http://secunia.com/advisories/61888
- http://lists.opensuse.org/opensuse-security-announce/2014-06/msg00002.html
- http://lists.opensuse.org/opensuse-security-announce/2014-06/msg00015.html
CVSS Scores
version 3.1