Release date: 2012-03-21
Updated on: 2012-03-22
Affected Systems:
GNU Libtasn1 1 2.11
GNU GnuTLS 3.0.15
GNU GnuTLS 3.0.14
Unaffected system:
GNU Libtasn1 1 2.12
GNU GnuTLS 3.0.16
Description:
--------------------------------------------------------------------------------
Bugtraq id: 52668
Cve id: CVE-2012-1569
LibtASN1 is a Linux and UNIX-based ASN.1 structure management library.
Several Functions in GNU Libtasn1 that use the ASN.1 Length Decoding logic determine that the returned value of asn1_get_length_der is always smaller than the length of the closed ASN.1 structure, triggering the Remote Memory Corruption Vulnerability, as a result, arbitrary code is executed in the affected application.
<* Source: Matthew Hall
Link: http://blog.mudynamics.com/2012/03/20/gnutls-and-libtasn1-vulns/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
GNU
---
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.gnu.org