Stack-based buffer overflow in libtASN1 - CVE-2015-2806

 

Stack-based buffer overflow in libtASN1 - CVE-2015-2806

Published: December 21, 2016 / Updated: August 3, 2017


Vulnerability identifier: #VU1590
CSH Severity: Low
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2015-2806
CWE-ID: CWE-121
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass security restrictions.

The weakness exists due to stack-based buffer overflow in asn1_der_decoding. A remote attacker can trigger memory corruption and have unspecified impact on the system.

Affected software

libtASN1
Arch Linux
Debian Linux
Gentoo Linux
Red Hat Enterprise Linux Server
Fedora
Ubuntu
libtasn1 (Alpine package)
mingw-p11-kit
mingw-gnutls
mingw-libtasn1
libtasn1

How to mitigate CVE-2015-2806

Update to version 4.4 or later.

libtasn1 (Alpine package) - update to 3.6-r1
mingw-p11-kit - update to 0.20.7-1.el7
mingw-gnutls - addressed in versions 3.3.14-1.el7, 3.3.14-1.fc21, 3.3.14-1.fc22
mingw-libtasn1 - addressed in versions 4.4-1.el7, 4.4-1.fc21, 4.4-1.fc22
libtasn1 - addressed in versions 4.4-1.fc21, 4.4-1.fc22

External References

Related Security Bulletins