libtasn1: denial of service
| Package(s): | libtasn1 | CVE #(s): | CVE-2016-4008 | ||||||||||||||||||||||||||||||||||||||||||||
| Created: | April 15, 2016 | Updated: | May 31, 2016 | ||||||||||||||||||||||||||||||||||||||||||||
| Description: | From the Red Hat bugzilla entry:
The libtasn1 library, in its 4.7 version, can loop for a long time or indefinitely when it is used to parse DER representations of X509 certificates, leading to a denial of service. Some of these loops may in addition increase heap or stack usage, leading to more issues. | ||||||||||||||||||||||||||||||||||||||||||||||
| Alerts: |
| ||||||||||||||||||||||||||||||||||||||||||||||
