LWN.net Logo

gnutls: denial of service

Package(s):gnutls CVE #(s):CVE-2006-0645
Created:February 13, 2006 Updated:March 6, 2006
Description: Several flaws were found in the way libtasn1 decodes DER. An attacker could create a carefully crafted invalid X.509 certificate in such a way that could trigger this flaw if parsed by an application that uses GNU TLS. This could lead to a denial of service (application crash). It is not certain if this issue could be escalated to allow arbitrary code execution.
Alerts:
Debian DSA-986-1 2006-03-06
Debian DSA-985-1 2006-03-06
Fedora-Legacy FLSA:181014 2006-02-27
Gentoo 200602-08 2006-02-16
Ubuntu USN-251-1 2006-02-16
Mandriva MDKSA-2006:039 2006-02-13
Fedora FEDORA-2006-107 2006-02-10
Red Hat RHSA-2006:0207-01 2006-02-10

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds