Input validation error in libtASN1 - CVE-2014-3467
Published: June 5, 2014 / Updated: August 4, 2020
Vulnerability identifier: #VU33843
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2014-3467
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to perform service disruption.
Multiple unspecified vulnerabilities in the DER decoder in GNU Libtasn1 before 3.6, as used in GnuTLS, allow remote attackers to cause a denial of service (out-of-bounds read) via crafted ASN.1 data.
Affected software
libtASN1
Amazon Linux AMI
Gentoo Linux
SUSE Linux
Slackware Linux
libtasn1 (Alpine package)
Amazon Linux AMI
Gentoo Linux
SUSE Linux
Slackware Linux
libtasn1 (Alpine package)
How to mitigate CVE-2014-3467
Install update from vendor's website.
libtASN1 - update to 3.6
libtasn1 (Alpine package) - update to 2.14-r1
libtasn1 (Alpine package) - update to 2.14-r1
External References
- http://advisories.mageia.org/MGASA-2014-0247.html
- http://linux.oracle.com/errata/ELSA-2014-0594.html
- http://linux.oracle.com/errata/ELSA-2014-0596.html
- http://lists.gnu.org/archive/html/help-libtasn1/2014-05/msg00006.html
- http://lists.opensuse.org/opensuse-security-announce/2014-06/msg00002.html
- http://lists.opensuse.org/opensuse-security-announce/2014-06/msg00015.html
- http://rhn.redhat.com/errata/RHSA-2014-0594.html
- http://rhn.redhat.com/errata/RHSA-2014-0596.html
- http://rhn.redhat.com/errata/RHSA-2014-0687.html
- http://rhn.redhat.com/errata/RHSA-2014-0815.html
- http://secunia.com/advisories/58591
- http://secunia.com/advisories/58614
- http://secunia.com/advisories/59021
- http://secunia.com/advisories/59057
- http://secunia.com/advisories/59408
- http://secunia.com/advisories/60320
- http://secunia.com/advisories/60415
- http://secunia.com/advisories/61888
- http://support.f5.com/kb/en-us/solutions/public/15000/400/sol15423.html
- http://www.debian.org/security/2014/dsa-3056
- http://www.mandriva.com/security/advisories?name=MDVSA-2015:116
- http://www.novell.com/support/kb/doc.php?id=7015302
- http://www.novell.com/support/kb/doc.php?id=7015303
- https://bugzilla.redhat.com/show_bug.cgi?id=1102022
Related Security Bulletins
- Input validation error in GNU libtASN1
- Input validation error in libtasn1 (Alpine package)
- SUSE Linux update for libtasn1
- SUSE Linux update for GnuTLS
- SUSE Linux update for GnuTLS
- SUSE Linux update for gnutls
- Amazon Linux AMI update for libtasn1
- Gentoo update for GNU Libtasn1
- Slackware Linux update for libtasn1
- Slackware Linux update for gnutls