CVE-2015-3622

Published: 01 May 2015

The _asn1_extract_der_octet function in lib/decoding.c in GNU Libtasn1 before 4.5 allows remote attackers to cause a denial of service (out-of-bounds heap read) via a crafted certificate.

Priority

Medium

Status

Package Release Status
libtasn1-3
Launchpad, Ubuntu, Debian
Upstream Needs triage

Ubuntu 14.04 ESM (Trusty Tahr) Does not exist

libtasn1-6
Launchpad, Ubuntu, Debian
Upstream
Released (4.4-3)
Ubuntu 14.04 ESM (Trusty Tahr)
Released (3.4-3ubuntu0.3)
Patches:
Upstream: http://git.savannah.gnu.org/gitweb/?p=libtasn1.git;a=commit;h=f979435823a02f842c41d49cd41cc81f25b5d677