Buffer overflow in libtASN1 - CVE-2017-6891

 

Buffer overflow in libtASN1 - CVE-2017-6891

Published: June 2, 2017


Vulnerability identifier: #VU6890
CSH Severity: Medium
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-6891
CWE-ID: CWE-121
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

A remote attacker can execute arbitrary code on the target system.

The vulnerability exists due to a boundary error in "asn1_find_node()" function (lib/parser_aux.c) within GnuTLS libtasn1 version 4.10 when processing a specially crafted assignments file via the e.g. asn1Coding utility. A remote attacker can trick the victim into opening a specially crafted file, trigger stack-based buffer overflow and execute arbitrary code with privileges of the current user.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.

Affected software

libtASN1
Arch Linux
Gentoo Linux
Debian Linux
Fedora
SUSE Linux Enterprise Server
Ubuntu
Opensuse
libtasn1 (Alpine package)
libtasn1
libtasn1-6
libtasn1-6-32bit
libtasn1-6-debuginfo
libtasn1-6-debuginfo-32bit
libtasn1-debuginfo
libtasn1-debugsource
mingw-libtasn1

How to mitigate CVE-2017-6891

Install update form GIT repository.

libtasn1 (Alpine package) - update to 4.7-r2
libtasn1 - update to 3.7-13.7.1
libtasn1-6 - update to 3.7-13.7.1
libtasn1-6-32bit - update to 3.7-13.7.1
libtasn1-6-debuginfo - update to 3.7-13.7.1
libtasn1-6-debuginfo-32bit - update to 3.7-13.7.1
libtasn1-debuginfo - update to 3.7-13.7.1
libtasn1-debugsource - update to 3.7-13.7.1
mingw-libtasn1 - addressed in versions 4.12-1.el7, 4.12-1.fc26
libtasn1 - addressed in versions 4.12-1.fc25, 4.12-1.fc26

External References

Related Security Bulletins