2012-03-26 21:55:01 2018-01-18 03:29:13

The asn1_get_length_der function in decoding.c in GNU Libtasn1 before 2.12, as used in GnuTLS before 3.0.16 and other products, does not properly handle certain large length values, which allows remote attackers to cause a denial of service (heap memory corruption and application crash) or possibly have unspecified other impact via a crafted ASN.1 structure.

Vector

NETWORK

Complexity

LOW

Authentication

NONE

Confidentiality

NONE

Integrity

NONE

Availability

PARTIAL
GNU Libtasn1 2.11 GNU Libtasn1 2.10 GNU Libtasn1 2.9 GNU Libtasn1 2.8 GNU Libtasn1 2.7 GNU Libtasn1 2.6 GNU Libtasn1 2.5 GNU Libtasn1 2.4 GNU Libtasn1 2.3 GNU Libtasn1 2.2 GNU Libtasn1 2.1 GNU Libtasn1 2.0 GNU Libtasn1 1.8 GNU Libtasn1 1.7 GNU Libtasn1 1.6 GNU Libtasn1 1.5 GNU Libtasn1 1.4 GNU Libtasn1 1.3 GNU Libtasn1 1.2 GNU Libtasn1 1.1 GNU Libtasn1 1.0 GNU Libtasn1 0.3.10 GNU Libtasn1 0.3.9 GNU Libtasn1 0.3.8 GNU Libtasn1 0.3.7 GNU Libtasn1 0.3.6 GNU Libtasn1 0.3.5 GNU Libtasn1 0.3.4 GNU Libtasn1 0.3.3 GNU Libtasn1 0.3.2 GNU Libtasn1 0.3.1 GNU Libtasn1 0.3.0 GNU Libtasn1 0.2.18 GNU Libtasn1 0.2.17 GNU Libtasn1 0.2.16 GNU Libtasn1 0.2.15 GNU Libtasn1 0.2.14 GNU Libtasn1 0.2.13 GNU Libtasn1 0.2.12 GNU Libtasn1 0.2.11 GNU Libtasn1 0.2.10 GNU Libtasn1 0.2.9 GNU Libtasn1 0.2.8 GNU Libtasn1 0.2.7 GNU Libtasn1 0.2.6 GNU Libtasn1 0.2.5 GNU Libtasn1 0.2.4 GNU Libtasn1 0.2.3 GNU Libtasn1 0.2.2 GNU Libtasn1 0.2.1 GNU Libtasn1 0.2.0 GNU Libtasn1 0.1.2 GNU Libtasn1 0.1.1 GNU Libtasn1 0.1.0 GNU GnuTLS 3.0.15 GNU GnuTLS 3.0.14 GNU GnuTLS 3.0.13 GNU GnuTLS 3.0.12 GNU GnuTLS 3.0.11 GNU GnuTLS 3.0.10 GNU GnuTLS 3.0.9 GNU GnuTLS 3.0.8 GNU GnuTLS 3.0.7 GNU GnuTLS 3.0.6 GNU GnuTLS 3.0.5 GNU GnuTLS 3.0.4 GNU GnuTLS 3.0.3 GNU GnuTLS 3.0.2 GNU GnuTLS 3.0.1 GNU GnuTLS 3.0.0 GNU TLS 3.0 GNU GnuTLS 2.12.14 GNU GnuTLS 2.12.13 GNU GnuTLS 2.12.12 GNU GnuTLS 2.12.11 GNU GnuTLS 2.12.10 GNU GnuTLS 2.12.9 GNU GnuTLS 2.12.8 GNU GnuTLS 2.12.7 GNU GnuTLS 2.12.6.1 GNU GnuTLS 2.12.6 GNU GnuTLS 2.12.5 GNU GnuTLS 2.12.4 GNU GnuTLS 2.12.3 GNU GnuTLS 2.12.2 GNU GnuTLS 2.12.1 GNU GnuTLS 2.12.0 GNU GnuTLS 2.10.5 GNU GnuTLS 2.10.4 GNU GnuTLS 2.10.3 GNU GnuTLS 2.10.2 GNU GnuTLS 2.10.1 GNU GnuTLS 2.10.0 GNU GnuTLS 2.8.6 GNU GnuTLS 2.8.5 GNU GnuTLS 2.8.4 GNU GnuTLS 2.8.3 GNU GnuTLS 2.8.2 GNU GnuTLS 2.8.1 GNU GnuTLS 2.8.0 GNU GnuTLS 2.7.4 GNU GnuTLS 2.6.6 GNU GnuTLS 2.6.5 GNU GnuTLS 2.6.4 GNU GnuTLS 2.6.3 GNU GnuTLS 2.6.2 GNU GnuTLS 2.6.1 GNU GnuTLS 2.6.0 GNU GnuTLS 2.5.0 GNU GnuTLS 2.4.3 GNU GnuTLS 2.4.2 GNU GnuTLS 2.4.1 GNU GnuTLS 2.4.0 GNU GnuTLS 2.3.11 GNU GnuTLS 2.3.10 GNU GnuTLS 2.3.9 GNU GnuTLS 2.3.8 GNU GnuTLS 2.3.7 GNU GnuTLS 2.3.6 GNU GnuTLS 2.3.5 GNU GnuTLS 2.3.4 GNU GnuTLS 2.3.3 GNU GnuTLS 2.3.2 GNU GnuTLS 2.3.1 GNU GnuTLS 2.3.0 GNU GnuTLS 2.2.5 GNU GnuTLS 2.2.4 GNU GnuTLS 2.2.3 GNU GnuTLS 2.2.2 GNU GnuTLS 2.2.1 GNU GnuTLS 2.2.0 GNU GnuTLS 2.1.8 GNU GnuTLS 2.1.7 GNU GnuTLS 2.1.6 GNU GnuTLS 2.1.5 GNU GnuTLS 2.1.4 GNU GnuTLS 2.1.3 GNU GnuTLS 2.1.2 GNU GnuTLS 2.1.1 GNU GnuTLS 2.1.0 GNU GnuTLS 2.0.4 GNU GnuTLS 2.0.3 GNU GnuTLS 2.0.2 GNU GnuTLS 2.0.1 GNU GnuTLS 2.0.0 GNU GnuTLS 1.7.19 GNU GnuTLS 1.7.18 GNU GnuTLS 1.7.17 GNU GnuTLS 1.7.16 GNU GnuTLS 1.7.15 GNU GnuTLS 1.7.14 GNU GnuTLS 1.7.13 GNU GnuTLS 1.7.12 GNU GnuTLS 1.7.11 GNU GnuTLS 1.7.10 GNU GnuTLS 1.7.9 GNU GnuTLS 1.7.8 GNU GnuTLS 1.7.7 GNU GnuTLS 1.7.6 GNU GnuTLS 1.7.5 GNU GnuTLS 1.7.4 GNU GnuTLS 1.7.3 GNU GnuTLS 1.7.2 GNU GnuTLS 1.7.1 GNU GnuTLS 1.7.0 GNU GnuTLS 1.6.3 GNU GnuTLS 1.6.2 GNU GnuTLS 1.6.1 GNU GnuTLS 1.6.0 GNU GnuTLS 1.5.5 GNU GnuTLS 1.5.4 GNU GnuTLS 1.5.3 GNU GnuTLS 1.5.2 GNU GnuTLS 1.5.1 GNU GnuTLS 1.5.0 GNU GnuTLS 1.4.5 GNU GnuTLS 1.4.4 GNU GnuTLS 1.4.3 GNU GnuTLS 1.4.2 GNU GnuTLS 1.4.1 GNU GnuTLS 1.4.0 GNU GnuTLS 1.3.5 GNU GnuTLS 1.3.4 GNU GnuTLS 1.3.3 GNU GnuTLS 1.3.2 GNU GnuTLS 1.3.1 GNU GnuTLS 1.3.0 GNU GnuTLS 1.2.11 GNU GnuTLS 1.2.10 GNU GnuTLS 1.2.9 GNU GnuTLS 1.2.8.1a1 GNU GnuTLS 1.2.8 GNU GnuTLS 1.2.7 GNU GnuTLS 1.2.6 GNU GnuTLS 1.2.5 GNU GnuTLS 1.2.4 GNU GnuTLS 1.2.3 GNU GnuTLS 1.2.2 GNU GnuTLS 1.2.1 GNU GnuTLS 1.2.0 GNU GnuTLS 1.1.23 GNU GnuTLS 1.1.22 GNU GnuTLS 1.1.21 GNU GnuTLS 1.1.20 GNU GnuTLS 1.1.19 GNU GnuTLS 1.1.18 GNU GnuTLS 1.1.17 GNU GnuTLS 1.1.16 GNU GnuTLS 1.1.15 GNU GnuTLS 1.1.14 GNU GnuTLS 1.1.13 GNU GnuTLS 1.0.25 GNU GnuTLS 1.0.24 GNU GnuTLS 1.0.23 GNU GnuTLS 1.0.22 GNU GnuTLS 1.0.21 GNU GnuTLS 1.0.20 GNU GnuTLS 1.0.19 GNU GnuTLS 1.0.18 GNU GnuTLS 1.0.17 GNU GnuTLS 1.0.16