Input validation error in libtASN1 - CVE-2014-3469
Published: June 5, 2014 / Updated: July 28, 2020
Vulnerability identifier: #VU32528
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2014-3469
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows context-dependent attackers to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can cause a denial of service (NULL pointer dereference and crash) via a NULL value in an ivalue argument.
Affected software
libtASN1
Amazon Linux AMI
Gentoo Linux
SUSE Linux
Slackware Linux
libtasn1 (Alpine package)
Amazon Linux AMI
Gentoo Linux
SUSE Linux
Slackware Linux
libtasn1 (Alpine package)
How to mitigate CVE-2014-3469
Update to version 3.6.
libtASN1 - update to 3.6
libtasn1 (Alpine package) - update to 2.14-r1
libtasn1 (Alpine package) - update to 2.14-r1
External References
- http://advisories.mageia.org/MGASA-2014-0247.html
- http://linux.oracle.com/errata/ELSA-2014-0594.html
- http://linux.oracle.com/errata/ELSA-2014-0596.html
- http://lists.gnu.org/archive/html/help-libtasn1/2014-05/msg00006.html
- http://lists.opensuse.org/opensuse-security-announce/2014-06/msg00002.html
- http://lists.opensuse.org/opensuse-security-announce/2014-06/msg00015.html
- http://rhn.redhat.com/errata/RHSA-2014-0594.html
- http://rhn.redhat.com/errata/RHSA-2014-0596.html
- http://rhn.redhat.com/errata/RHSA-2014-0687.html
- http://rhn.redhat.com/errata/RHSA-2014-0815.html
- http://secunia.com/advisories/58591
- http://secunia.com/advisories/58614
- http://secunia.com/advisories/59021
- http://secunia.com/advisories/59057
- http://secunia.com/advisories/59408
- http://secunia.com/advisories/60320
- http://secunia.com/advisories/60415
- http://secunia.com/advisories/61888
- http://www.debian.org/security/2014/dsa-3056
- http://www.mandriva.com/security/advisories?name=MDVSA-2015:116
- http://www.novell.com/support/kb/doc.php?id=7015302
- http://www.novell.com/support/kb/doc.php?id=7015303
- https://bugzilla.redhat.com/show_bug.cgi?id=1102329
Related Security Bulletins
- Input validation error in GNU libtASN1
- Input validation error in libtasn1 (Alpine package)
- SUSE Linux update for libtasn1
- SUSE Linux update for GnuTLS
- SUSE Linux update for GnuTLS
- SUSE Linux update for gnutls
- Amazon Linux AMI update for libtasn1
- Gentoo update for GNU Libtasn1
- Slackware Linux update for libtasn1
- Slackware Linux update for gnutls