CVE-2014-3467
published 2014-06-05CVE-2014-3467: Multiple unspecified vulnerabilities in the DER decoder in GNU Libtasn1 before 3.6, as used in GnuTLS, allow remote attackers to cause a denial of service…
PriorityP427medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
6.80%
93.3th percentile
Multiple unspecified vulnerabilities in the DER decoder in GNU Libtasn1 before 3.6, as used in GnuTLS, allow remote attackers to cause a denial of service (out-of-bounds read) via crafted ASN.1 data.
Affected
34 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | libtasn1-6 | < libtasn1-6 3.6-1 (bookworm) | libtasn1-6 3.6-1 (bookworm) |
| f5 | arx_firmware | 6.0.0 – 6.4.0 | — |
| gnu | gnutls | < 3.5.7 | 3.5.7 |
| gnu | libtasn1 | < 3.6 | 3.6 |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-pfh9-rfxw-j6x2: Multiple unspecified vulnerabilities in the DER decoder in GNU Libtasn1 before 3
ghsa_unreviewed·2022-05-13
CVE-2014-3467 [MEDIUM] GHSA-pfh9-rfxw-j6x2: Multiple unspecified vulnerabilities in the DER decoder in GNU Libtasn1 before 3
Multiple unspecified vulnerabilities in the DER decoder in GNU Libtasn1 before 3.6, as used in GnuTLS, allow remote attackers to cause a denial of service (out-of-bounds read) via crafted ASN.1 data.
OSV
libtasn1-3, libtasn1-6 vulnerabilities
osv·2014-07-22·CVSS 5.0
CVE-2014-3467 [MEDIUM] libtasn1-3, libtasn1-6 vulnerabilities
libtasn1-3, libtasn1-6 vulnerabilities
It was discovered that Libtasn1 incorrectly handled certain ASN.1 data
structures. An attacker could exploit this with specially crafted ASN.1
data and cause applications using Libtasn1 to crash, resulting in a denial
of service. (CVE-2014-3467)
It was discovered that Libtasn1 incorrectly handled negative bit lengths.
An attacker could exploit this with specially crafted ASN.1 data and cause
applications using Libtasn1 to crash, resulting in a denial of service, or
possibly execute arbitrary code. (CVE-2014-3468)
It was discovered that Libtasn1 incorrectly handled certain ASN.1 data. An
attacker could exploit this with specially crafted ASN.1 data and cause
applications using Libtasn1 to crash, resulting in a denial of service.
(CVE-2014-3469)
OSV
CVE-2014-3467: Multiple unspecified vulnerabilities in the DER decoder in GNU Libtasn1 before 3
osv·2014-06-05·CVSS 5.0
CVE-2014-3467 [MEDIUM] CVE-2014-3467: Multiple unspecified vulnerabilities in the DER decoder in GNU Libtasn1 before 3
Multiple unspecified vulnerabilities in the DER decoder in GNU Libtasn1 before 3.6, as used in GnuTLS, allow remote attackers to cause a denial of service (out-of-bounds read) via crafted ASN.1 data.
Ubuntu
Libtasn1 vulnerabilities
vendor_ubuntu·2014-07-22·CVSS 5.0
CVE-2014-3467 [MEDIUM] Libtasn1 vulnerabilities
Title: Libtasn1 vulnerabilities
Summary: Libtasn1 could be made to crash or run programs as your login if it
processed specially crafted data.
It was discovered that Libtasn1 incorrectly handled certain ASN.1 data
structures. An attacker could exploit this with specially crafted ASN.1
data and cause applications using Libtasn1 to crash, resulting in a denial
of service. (CVE-2014-3467)
It was discovered that Libtasn1 incorrectly handled negative bit lengths.
An attacker could exploit this with specially crafted ASN.1 data and cause
applications using Libtasn1 to crash, resulting in a denial of service, or
possibly execute arbitrary code. (CVE-2014-3468)
It was discovered that Libtasn1 incorrectly handled certain ASN.1 data. An
attacker could exploit this with specially crafted ASN.1 da
Red Hat
libtasn1: multiple boundary check issues
vendor_redhat·2014-05-25·CVSS 5.0
CVE-2014-3467 [MEDIUM] CWE-125 libtasn1: multiple boundary check issues
libtasn1: multiple boundary check issues
Multiple unspecified vulnerabilities in the DER decoder in GNU Libtasn1 before 3.6, as used in GnuTLS, allow remote attackers to cause a denial of service (out-of-bounds read) via crafted ASN.1 data.
Package: gnutls (Red Hat Enterprise Linux 4) - Will not fix
Package: mingw32-gnutls (Red Hat Enterprise Linux 6) - Will not fix
Debian
CVE-2014-3467: libtasn1-6 - Multiple unspecified vulnerabilities in the DER decoder in GNU Libtasn1 before 3...
vendor_debian·2014·CVSS 5.0
CVE-2014-3467 [MEDIUM] CVE-2014-3467: libtasn1-6 - Multiple unspecified vulnerabilities in the DER decoder in GNU Libtasn1 before 3...
Multiple unspecified vulnerabilities in the DER decoder in GNU Libtasn1 before 3.6, as used in GnuTLS, allow remote attackers to cause a denial of service (out-of-bounds read) via crafted ASN.1 data.
Scope: local
bookworm: resolved (fixed in 3.6-1)
bullseye: resolved (fixed in 3.6-1)
forky: resolved (fixed in 3.6-1)
sid: resolved (fixed in 3.6-1)
trixie: resolved (fixed in 3.6-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-3467 CVE-2014-3469 CVE-2014-3468 libtasn1: various flaws [fedora-all]
bugzilla·2014-05-30·CVSS 5.0
CVE-2014-3467 [MEDIUM] CVE-2014-3467 CVE-2014-3469 CVE-2014-3468 libtasn1: various flaws [fedora-all]
CVE-2014-3467 CVE-2014-3469 CVE-2014-3468 libtasn1: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
NOTE: this issue affects multiple
Bugzilla
CVE-2014-3467 CVE-2014-3469 CVE-2014-3468 mingw32-gnutls: various flaws [epel-5]
bugzilla·2014-05-30·CVSS 5.0
CVE-2014-3467 [MEDIUM] CVE-2014-3467 CVE-2014-3469 CVE-2014-3468 mingw32-gnutls: various flaws [epel-5]
CVE-2014-3467 CVE-2014-3469 CVE-2014-3468 mingw32-gnutls: various flaws [epel-5]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
epel-5 tracking bug for mi
Bugzilla
CVE-2014-3467 CVE-2014-3469 CVE-2014-3468 mingw-libtasn1: various flaws [fedora-all]
bugzilla·2014-05-30·CVSS 5.0
CVE-2014-3467 [MEDIUM] CVE-2014-3467 CVE-2014-3469 CVE-2014-3468 mingw-libtasn1: various flaws [fedora-all]
CVE-2014-3467 CVE-2014-3469 CVE-2014-3468 mingw-libtasn1: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
NOTE: this issue affects mu
Bugzilla
CVE-2014-3467 libtasn1: multiple boundary check issues
bugzilla·2014-05-28·CVSS 5.0
CVE-2014-3467 [MEDIUM] CVE-2014-3467 libtasn1: multiple boundary check issues
CVE-2014-3467 libtasn1: multiple boundary check issues
Multiple buffer boundary check issues were discovered in libtasn1 library, causing it to read beyond the boundary of an allocated buffer. An untrusted ASN.1 input could cause an application using the library to crash.
The libtasn1 library is used by the GnuTLS library to parse X.509 certificates. The gnutls packages in Red Hat Enterprise Linux 5 and earlier use bundled libtasn1, packages in Red Hat Enterprise Linux 6 and later depend on the library provided by a separate libtasn1 package.
Upstream commits:
http://git.savannah.gnu.org/cgit/libtasn1.git/commit/?id=ff3b5c68cc32e30d19edbbc3a962b2266029f3cc
http://git.savannah.gnu.org/cgit/libtasn1.git/commit/?id=0e80d79db71747644394fe3472dad28cd3e7b00b
http://git.savannah.gnu.org/cgit/l
arXiv
Vital: Vulnerability-Oriented Symbolic Execution via Type-Unsafe Pointer-Guided Monte Carlo Tree Search
arxiv_fulltext·2025-12-12
Vital: Vulnerability-Oriented Symbolic Execution via Type-Unsafe Pointer-Guided Monte Carlo Tree Search
: Vulnerability-Oriented Symbolic Execution via Type-Unsafe Pointer-Guided Monte Carlo Tree Search
Haoxin Tu
Partial work was done when Haoxin was visiting the MPI Software Security Group led by Prof. Marcel Böhme.
Singapore Management University
Singapore
[email protected]
Lingxiao Jiang
Singapore Management University
Singapore
[email protected]
Marcel Böhme
Max Planck Institute for Security and Privacy
Germany
[email protected]
Haoxin Tu, Lingxiao Jiang, and Marcel Böhme
## Abstract
How do we find new memory safety bugs effectively when navigating a symbolic execution tree that suffers from the well-known path explosion challenge?
Existing solutions either adopt path search heuristics to maximize coverage rate or chopped symbolic execution to skip uninteresting code
http://advisories.mageia.org/MGASA-2014-0247.htmlhttp://linux.oracle.com/errata/ELSA-2014-0594.htmlhttp://linux.oracle.com/errata/ELSA-2014-0596.htmlhttp://lists.gnu.org/archive/html/help-libtasn1/2014-05/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-06/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-06/msg00015.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0594.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0596.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0687.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0815.htmlhttp://secunia.com/advisories/58591http://secunia.com/advisories/58614http://secunia.com/advisories/59021http://secunia.com/advisories/59057http://secunia.com/advisories/59408http://secunia.com/advisories/60320http://secunia.com/advisories/60415http://secunia.com/advisories/61888http://support.f5.com/kb/en-us/solutions/public/15000/400/sol15423.htmlhttp://www.debian.org/security/2014/dsa-3056http://www.mandriva.com/security/advisories?name=MDVSA-2015:116http://www.novell.com/support/kb/doc.php?id=7015302http://www.novell.com/support/kb/doc.php?id=7015303https://bugzilla.redhat.com/show_bug.cgi?id=1102022http://advisories.mageia.org/MGASA-2014-0247.htmlhttp://linux.oracle.com/errata/ELSA-2014-0594.htmlhttp://linux.oracle.com/errata/ELSA-2014-0596.htmlhttp://lists.gnu.org/archive/html/help-libtasn1/2014-05/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-06/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-06/msg00015.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0594.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0596.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0687.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0815.htmlhttp://secunia.com/advisories/58591http://secunia.com/advisories/58614http://secunia.com/advisories/59021http://secunia.com/advisories/59057http://secunia.com/advisories/59408http://secunia.com/advisories/60320http://secunia.com/advisories/60415http://secunia.com/advisories/61888http://support.f5.com/kb/en-us/solutions/public/15000/400/sol15423.htmlhttp://www.debian.org/security/2014/dsa-3056http://www.mandriva.com/security/advisories?name=MDVSA-2015:116http://www.novell.com/support/kb/doc.php?id=7015302http://www.novell.com/support/kb/doc.php?id=7015303https://bugzilla.redhat.com/show_bug.cgi?id=1102022
2014-06-05
Published