|
|
Log in / Subscribe / Register

libtasn1: denial of service

Package(s):libtasn1 CVE #(s):CVE-2016-4008
Created:April 15, 2016 Updated:May 31, 2016
Description: From the Red Hat bugzilla entry:

The libtasn1 library, in its 4.7 version, can loop for a long time or indefinitely when it is used to parse DER representations of X509 certificates, leading to a denial of service. Some of these loops may in addition increase heap or stack usage, leading to more issues.

Alerts:
openSUSE openSUSE-SU-2016:1674-1 libtasn1 2016-06-24
openSUSE openSUSE-SU-2016:1567-1 libtasn1 2016-06-14
Debian-LTS DLA-495-1 libtasn1-3 2016-05-30
Mageia MGASA-2016-0170 libtasn1 2016-05-11
Debian DSA-3568-1 libtasn1-6 2016-05-05
Ubuntu USN-2957-2 libtasn1-6 2016-05-02
Ubuntu USN-2957-1 libtasn1-3, libtasn1-6 2016-05-02
Fedora FEDORA-2016-96bfd9e873 libtasn1 2016-04-27
Fedora FEDORA-2016-383b8250e6 libtasn1 2016-04-22
Arch Linux ASA-201604-9 libtasn1 2016-04-17
Fedora FEDORA-2016-048ffb6235 libtasn1 2016-04-15

to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds