GNU Libtasn1 'decoding. c' Heap Buffer Overflow Vulnerability
GNU Libtasn1 'decoding. c' Heap Buffer Overflow Vulnerability
Release date:
Updated on:
Affected Systems:
GNU Libtasn1
Unaffected system:
GNU Libtasn1 <4.5
Description:
Bugtraq id: 74419
CVE (CAN) ID: CVE-2015-3622
GNU Libtasn1 is an independent library written in C language. It is used to operate ASN.1 objects including DER/BER encoding and decoding.
In versions earlier than GNU Libtasn1 4.5, the _ asn‑extract_der_octet function of lib/decoding. c has the heap buffer overflow vulnerability. Remote attackers can exploit this vulnerability to cause DoS by constructing a certificate.
<* Source: Hanno B & amp; ouml; ck
*>
Suggestion:
Vendor patch:
GNU
---
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Https://lists.gnu.org/archive/html/help-libtasn1/2015-04/msg00000.html
This article permanently updates the link address: