---
title: "CVE-2006-0645\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2006-0645?format=md
keywords: index, follow
---

# CVE-2006-0645

Publication date 10 February 2006

Last updated 17 July 2025

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

Tiny ASN.1 Library (libtasn1) before 0.2.18, as used by (1) GnuTLS 1.2.x
before 1.2.10 and 1.3.x before 1.3.4, and (2) GNU Shishi, allows attackers
to crash the DER decoder and possibly execute arbitrary code via
"out-of-bounds access" caused by invalid input, as demonstrated by the
ProtoVer SSL test suite.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| libtasn1-2 | 7.04 feisty | Not in release |
| 6.10 edgy | Ignored end of life, was needed |
| 6.06 LTS dapper | Fixed 0.2.17-1ubuntu1 |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0645)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2006-0645)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2006-0645)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2006-0645)

### Related Ubuntu Security Notices (USN)

+ [USN-251-1](https://usn.ubuntu.com/USN-251-1)
+ libtasn vulnerability
+ 17 February 2006

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2006-0645>
