Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-3622

Опубликовано: 30 апр. 2015
Источник: redhat
CVSS3: 5.9
CVSS2: 4.3
EPSS Низкий

Описание

The _asn1_extract_der_octet function in lib/decoding.c in GNU Libtasn1 before 4.5 allows remote attackers to cause a denial of service (out-of-bounds heap read) via a crafted certificate.

A heap-based buffer overflow flaw was found in the way the libtasn1 library decoded certain DER-encoded inputs. A specially crafted DER-encoded input could cause an application using libtasn1 to perform an invalid read, causing the application to crash.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6libtasn1Will not fix
Red Hat Enterprise Virtualization 3mingw-virt-viewerFix deferred
Red Hat Enterprise Linux 7libtasn1FixedRHSA-2017:186001.08.2017

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-122
https://bugzilla.redhat.com/show_bug.cgi?id=1218141libtasn1: heap overflow flaw in _asn1_extract_der_octet()

EPSS

Процентиль: 90%
0.06062
Низкий

5.9 Medium

CVSS3

4.3 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 10 лет назад

The _asn1_extract_der_octet function in lib/decoding.c in GNU Libtasn1 before 4.5 allows remote attackers to cause a denial of service (out-of-bounds heap read) via a crafted certificate.

nvd
больше 10 лет назад

The _asn1_extract_der_octet function in lib/decoding.c in GNU Libtasn1 before 4.5 allows remote attackers to cause a denial of service (out-of-bounds heap read) via a crafted certificate.

debian
больше 10 лет назад

The _asn1_extract_der_octet function in lib/decoding.c in GNU Libtasn1 ...

github
больше 3 лет назад

The _asn1_extract_der_octet function in lib/decoding.c in GNU Libtasn1 before 4.5 allows remote attackers to cause a denial of service (out-of-bounds heap read) via a crafted certificate.

suse-cvrf
больше 9 лет назад

Security update for libtasn1

EPSS

Процентиль: 90%
0.06062
Низкий

5.9 Medium

CVSS3

4.3 Medium

CVSS2