First published: Tue Mar 20 2012(Updated: )
libtasn1 version 2.12 was released fixing the following issue: - Corrected DER decoding issue (reported by Matthew Hall). Added self check to detect the problem, see tests/Test_overflow.c. This problem can lead to at least remotely triggered crashes, see further analysis on the libtasn1 mailing list. <a href="http://thread.gmane.org/gmane.comp.gnu.libtasn1.general/53">http://thread.gmane.org/gmane.comp.gnu.libtasn1.general/53</a> Upstream and few limited details are available at: <a href="http://thread.gmane.org/gmane.comp.gnu.libtasn1.general/54">http://thread.gmane.org/gmane.comp.gnu.libtasn1.general/54</a> The behavior of asn1_get_length_der was changed to protect against accidental incorrect use, if though it was previously "working properly and as documented".
Affected Software | Affected Version | How to fix |
---|---|---|
libtasn1 (GNU) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-804920 is high due to potential remotely triggered crashes.
To fix REDHAT-BUG-804920, update to libtasn1 version 2.12 or later.
The issue in REDHAT-BUG-804920 is caused by a DER decoding flaw.
The problem in REDHAT-BUG-804920 was reported by Matthew Hall.
The affected software for REDHAT-BUG-804920 is GNU libtasn1.