Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2015:0901-1

Опубликовано: 17 июл. 2014
Источник: suse-cvrf

Описание

Security update for libtasn1

libtasn1 has been updated to fix three security issues:

* asn1_get_bit_der() could have returned negative bit length (CVE-2014-3468) * Multiple boundary check issues could have allowed DoS (CVE-2014-3467) * Possible DoS by NULL pointer dereference in asn1_read_value_type (CVE-2014-3469)

Security Issues:

* CVE-2014-3468 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3468> * CVE-2014-3467 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3467> * CVE-2014-3469 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3469>

Список пакетов

SUSE Linux Enterprise Desktop 11 SP3
libtasn1-1.5-1.28.1
libtasn1-3-1.5-1.28.1
libtasn1-3-32bit-1.5-1.28.1
SUSE Linux Enterprise Server 11 SP3
libtasn1-1.5-1.28.1
libtasn1-3-1.5-1.28.1
libtasn1-3-32bit-1.5-1.28.1
libtasn1-3-x86-1.5-1.28.1
SUSE Linux Enterprise Server 11 SP3-TERADATA
libtasn1-1.5-1.28.1
libtasn1-3-1.5-1.28.1
libtasn1-3-32bit-1.5-1.28.1
libtasn1-3-x86-1.5-1.28.1
SUSE Linux Enterprise Server for SAP Applications 11 SP3
libtasn1-1.5-1.28.1
libtasn1-3-1.5-1.28.1
libtasn1-3-32bit-1.5-1.28.1
libtasn1-3-x86-1.5-1.28.1
SUSE Linux Enterprise Software Development Kit 11 SP3
libtasn1-devel-1.5-1.28.1

Описание

Multiple unspecified vulnerabilities in the DER decoder in GNU Libtasn1 before 3.6, as used in GnuTLS, allow remote attackers to cause a denial of service (out-of-bounds read) via crafted ASN.1 data.


Затронутые продукты
SUSE Linux Enterprise Desktop 11 SP3:libtasn1-1.5-1.28.1
SUSE Linux Enterprise Desktop 11 SP3:libtasn1-3-1.5-1.28.1
SUSE Linux Enterprise Desktop 11 SP3:libtasn1-3-32bit-1.5-1.28.1
SUSE Linux Enterprise Server 11 SP3-TERADATA:libtasn1-1.5-1.28.1

Ссылки

Описание

The asn1_get_bit_der function in GNU Libtasn1 before 3.6 does not properly report an error when a negative bit length is identified, which allows context-dependent attackers to cause out-of-bounds access via crafted ASN.1 data.


Затронутые продукты
SUSE Linux Enterprise Desktop 11 SP3:libtasn1-1.5-1.28.1
SUSE Linux Enterprise Desktop 11 SP3:libtasn1-3-1.5-1.28.1
SUSE Linux Enterprise Desktop 11 SP3:libtasn1-3-32bit-1.5-1.28.1
SUSE Linux Enterprise Server 11 SP3-TERADATA:libtasn1-1.5-1.28.1

Ссылки

Описание

The (1) asn1_read_value_type and (2) asn1_read_value functions in GNU Libtasn1 before 3.6 allows context-dependent attackers to cause a denial of service (NULL pointer dereference and crash) via a NULL value in an ivalue argument.


Затронутые продукты
SUSE Linux Enterprise Desktop 11 SP3:libtasn1-1.5-1.28.1
SUSE Linux Enterprise Desktop 11 SP3:libtasn1-3-1.5-1.28.1
SUSE Linux Enterprise Desktop 11 SP3:libtasn1-3-32bit-1.5-1.28.1
SUSE Linux Enterprise Server 11 SP3-TERADATA:libtasn1-1.5-1.28.1

Ссылки

Описание

Stack-based buffer overflow in asn1_der_decoding in libtasn1 before 4.4 allows remote attackers to have unspecified impact via unknown vectors.


Затронутые продукты
SUSE Linux Enterprise Desktop 11 SP3:libtasn1-1.5-1.28.1
SUSE Linux Enterprise Desktop 11 SP3:libtasn1-3-1.5-1.28.1
SUSE Linux Enterprise Desktop 11 SP3:libtasn1-3-32bit-1.5-1.28.1
SUSE Linux Enterprise Server 11 SP3-TERADATA:libtasn1-1.5-1.28.1

Ссылки
Уязвимость SUSE-SU-2015:0901-1