Input validation error in libtASN1 and GnuTLS - CVE-2012-1569

 

Input validation error in libtASN1 and GnuTLS - CVE-2012-1569

Published: March 26, 2012 / Updated: August 11, 2020


Vulnerability identifier: #VU44184
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2012-1569
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to perform service disruption.

The asn1_get_length_der function in decoding.c in GNU Libtasn1 before 2.12, as used in GnuTLS before 3.0.16 and other products, does not properly handle certain large length values, which allows remote attackers to cause a denial of service (heap memory corruption and application crash) or possibly have unspecified other impact via a crafted ASN.1 structure.


Affected software

libtASN1
GnuTLS
Amazon Linux AMI
Gentoo Linux
Slackware Linux

How to mitigate CVE-2012-1569

Install update from vendor's website.


External References

Related Security Bulletins