LWN.net Logo

libtasn1-3: denial of service

Package(s):libtasn1-3 CVE #(s):CVE-2012-1569
Created:March 26, 2012 Updated:September 26, 2012
Description: From the Debian advisory:

Matthew Hall discovered that many callers of the asn1_get_length_der function did not check the result against the overall buffer length before processing it further. This could result in out-of-bounds memory accesses and application crashes. Applications using GNUTLS are exposed to this issue.

Alerts:
Debian DSA-2440-1 2012-03-24
Mandriva MDVSA-2012:039 2012-03-27
Red Hat RHSA-2012:0427-01 2012-03-27
Red Hat RHSA-2012:0428-01 2012-03-27
CentOS CESA-2012:0428 2012-03-28
CentOS CESA-2012:0427 2012-03-28
Scientific Linux SL-gnut-20120328 2012-03-28
Scientific Linux SL-libt-20120328 2012-03-28
Oracle ELSA-2012-0427 2012-03-28
Oracle ELSA-2012-0428 2012-03-28
Fedora FEDORA-2012-4409 2012-03-31
Fedora FEDORA-2012-4409 2012-03-31
Fedora FEDORA-2012-4342 2012-04-06
Fedora FEDORA-2012-4308 2012-04-06
Fedora FEDORA-2012-4417 2012-04-12
Fedora FEDORA-2012-4417 2012-04-12
Ubuntu USN-1436-1 2012-05-02
openSUSE openSUSE-SU-2012:0620-1 2012-05-15
Gentoo 201209-12 2012-09-25

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds