Out-of-bounds read in libtASN1 - CVE-2015-3622

 

Out-of-bounds read in libtASN1 - CVE-2015-3622

Published: August 3, 2017


Vulnerability identifier: #VU7690
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2015-3622
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause DoS conditions on the target system.

The weakness exists due to an error in the _asn1_extract_der_octet function in lib/decoding.c. A remote attacker can send a specially crafted certificate, trigger out-of-bounds heap read and cause the application to crash.

Successful exploitation of the vulnerability results in denial of service.

Affected software

libtASN1
Arch Linux
Debian Linux
Gentoo Linux
Red Hat Enterprise Linux Server
Fedora
Ubuntu
libtasn1 (Alpine package)
libtasn1
mingw-libtasn1

How to mitigate CVE-2015-3622

Update to version 4.5 or later.

libtasn1 (Alpine package) - addressed in versions 3.6-r1, 3.6-r2
libtasn1 - addressed in versions 4.5-1.fc21, 4.5-1.fc22
mingw-libtasn1 - update to 4.12-1.el7

External References

Related Security Bulletins