Buffer overflow in libtASN1 - CVE-2017-6891
Published: June 2, 2017
Vulnerability identifier: #VU6890
CSH Severity: Medium
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-6891
CWE-ID: CWE-121
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
A remote attacker can execute arbitrary code on the target system.
The vulnerability exists due to a boundary error in "asn1_find_node()" function (lib/parser_aux.c) within GnuTLS libtasn1 version 4.10 when processing a specially crafted assignments file via the e.g. asn1Coding utility. A remote attacker can trick the victim into opening a specially crafted file, trigger stack-based buffer overflow and execute arbitrary code with privileges of the current user.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
The vulnerability exists due to a boundary error in "asn1_find_node()" function (lib/parser_aux.c) within GnuTLS libtasn1 version 4.10 when processing a specially crafted assignments file via the e.g. asn1Coding utility. A remote attacker can trick the victim into opening a specially crafted file, trigger stack-based buffer overflow and execute arbitrary code with privileges of the current user.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
Affected software
libtASN1
Arch Linux
Gentoo Linux
Debian Linux
Fedora
SUSE Linux Enterprise Server
Ubuntu
Opensuse
libtasn1 (Alpine package)
libtasn1
libtasn1-6
libtasn1-6-32bit
libtasn1-6-debuginfo
libtasn1-6-debuginfo-32bit
libtasn1-debuginfo
libtasn1-debugsource
mingw-libtasn1
Arch Linux
Gentoo Linux
Debian Linux
Fedora
SUSE Linux Enterprise Server
Ubuntu
Opensuse
libtasn1 (Alpine package)
libtasn1
libtasn1-6
libtasn1-6-32bit
libtasn1-6-debuginfo
libtasn1-6-debuginfo-32bit
libtasn1-debuginfo
libtasn1-debugsource
mingw-libtasn1
How to mitigate CVE-2017-6891
Install update form GIT repository.
libtasn1 (Alpine package) - update to 4.7-r2
libtasn1 - update to 3.7-13.7.1
libtasn1-6 - update to 3.7-13.7.1
libtasn1-6-32bit - update to 3.7-13.7.1
libtasn1-6-debuginfo - update to 3.7-13.7.1
libtasn1-6-debuginfo-32bit - update to 3.7-13.7.1
libtasn1-debuginfo - update to 3.7-13.7.1
libtasn1-debugsource - update to 3.7-13.7.1
mingw-libtasn1 - addressed in versions 4.12-1.el7, 4.12-1.fc26
libtasn1 - addressed in versions 4.12-1.fc25, 4.12-1.fc26
libtasn1 - update to 3.7-13.7.1
libtasn1-6 - update to 3.7-13.7.1
libtasn1-6-32bit - update to 3.7-13.7.1
libtasn1-6-debuginfo - update to 3.7-13.7.1
libtasn1-6-debuginfo-32bit - update to 3.7-13.7.1
libtasn1-debuginfo - update to 3.7-13.7.1
libtasn1-debugsource - update to 3.7-13.7.1
mingw-libtasn1 - addressed in versions 4.12-1.el7, 4.12-1.fc26
libtasn1 - addressed in versions 4.12-1.fc25, 4.12-1.fc26
External References
Related Security Bulletins
- Arch Linux update for libtasn1
- Remote code execution in GNU Libtasn1
- Ubuntu update for GNU Libtasn1
- Ubuntu update for Libtasn1
- Arch Linux update for lib32-libtasn1
- Debian update for libtasn1-6
- Gentoo update for GNU Libtasn1
- OpenSUSE Linux update for libtasn1
- Buffer overflow in libtasn1 (Alpine package)
- SUSE update for libtasn1
- Fedora 26 update for libtasn1
- Fedora 25 update for libtasn1
- Fedora 26 update for mingw-libtasn1
- Fedora EPEL 7 update for mingw-libtasn1