|
|
| |
|
| |
libtasn1-3: denial of service
| Package(s): | libtasn1-3 |
CVE #(s): | CVE-2012-1569
|
| Created: | March 26, 2012 |
Updated: | September 26, 2012 |
| Description: |
From the Debian advisory:
Matthew Hall discovered that many callers of the asn1_get_length_der
function did not check the result against the overall buffer length
before processing it further. This could result in out-of-bounds
memory accesses and application crashes. Applications using GNUTLS
are exposed to this issue. |
| Alerts: |
|
( Log in to post comments)
|
|
|