GnuTLS libtasn1 "_ asnjavasltostr ()" DER Decoding Buffer Overflow Vulnerability
Release date:
Updated on:
Affected Systems:
GnuTLS libtasn1 <1, 4.4
Description:
GNU Libtasn1 is an independent library written in C language. It is used to operate ASN.1 objects including DER/BER encoding and decoding. GnuTLS uses Libtasn1 to process the X.509 structure, while GNU Shishi uses Libtasn1 to process the Kerberos V5 structure.
In versions earlier than GnuTLS libtasn1 4.4, a security vulnerability exists in the implementation of the "_ asn1_ltostr ()" function (lib/parser_aux.c), which can cause stack buffer overflow, attackers can exploit this vulnerability to execute arbitrary code.
<* Source: Hanno B & #246; ck
Link: http://secunia.com/advisories/63482/
*>
Suggestion:
Vendor patch:
GnuTLS
------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Https://www.gnu.org/software/libtasn1/
Http://lists.gnu.org/archive/html/help-libtasn1/2015-03/msg00002.html
This article permanently updates the link address: