CVE-2014-3468
published 2014-06-05CVE-2014-3468: The asn1_get_bit_der function in GNU Libtasn1 before 3.6 does not properly report an error when a negative bit length is identified, which allows…
PriorityP338high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
3.79%
88.8th percentile
The asn1_get_bit_der function in GNU Libtasn1 before 3.6 does not properly report an error when a negative bit length is identified, which allows context-dependent attackers to cause out-of-bounds access via crafted ASN.1 data.
Affected
34 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | libtasn1-6 | < libtasn1-6 3.6-1 (bookworm) | libtasn1-6 3.6-1 (bookworm) |
| f5 | arx_firmware | 6.0.0 – 6.4.0 | — |
| gnu | gnutls | < 3.5.7 | 3.5.7 |
| gnu | libtasn1 | < 3.6 | 3.6 |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qg3j-x87h-jwjm: The asn1_get_bit_der function in GNU Libtasn1 before 3
ghsa_unreviewed·2022-05-13
CVE-2014-3468 [HIGH] CWE-131 GHSA-qg3j-x87h-jwjm: The asn1_get_bit_der function in GNU Libtasn1 before 3
The asn1_get_bit_der function in GNU Libtasn1 before 3.6 does not properly report an error when a negative bit length is identified, which allows context-dependent attackers to cause out-of-bounds access via crafted ASN.1 data.
OSV
libtasn1-3, libtasn1-6 vulnerabilities
osv·2014-07-22·CVSS 5.0
CVE-2014-3467 [MEDIUM] libtasn1-3, libtasn1-6 vulnerabilities
libtasn1-3, libtasn1-6 vulnerabilities
It was discovered that Libtasn1 incorrectly handled certain ASN.1 data
structures. An attacker could exploit this with specially crafted ASN.1
data and cause applications using Libtasn1 to crash, resulting in a denial
of service. (CVE-2014-3467)
It was discovered that Libtasn1 incorrectly handled negative bit lengths.
An attacker could exploit this with specially crafted ASN.1 data and cause
applications using Libtasn1 to crash, resulting in a denial of service, or
possibly execute arbitrary code. (CVE-2014-3468)
It was discovered that Libtasn1 incorrectly handled certain ASN.1 data. An
attacker could exploit this with specially crafted ASN.1 data and cause
applications using Libtasn1 to crash, resulting in a denial of service.
(CVE-2014-3469)
OSV
CVE-2014-3468: The asn1_get_bit_der function in GNU Libtasn1 before 3
osv·2014-06-05·CVSS 7.5
CVE-2014-3468 [HIGH] CVE-2014-3468: The asn1_get_bit_der function in GNU Libtasn1 before 3
The asn1_get_bit_der function in GNU Libtasn1 before 3.6 does not properly report an error when a negative bit length is identified, which allows context-dependent attackers to cause out-of-bounds access via crafted ASN.1 data.
Ubuntu
Libtasn1 vulnerabilities
vendor_ubuntu·2014-07-22·CVSS 5.0
CVE-2014-3467 [MEDIUM] Libtasn1 vulnerabilities
Title: Libtasn1 vulnerabilities
Summary: Libtasn1 could be made to crash or run programs as your login if it
processed specially crafted data.
It was discovered that Libtasn1 incorrectly handled certain ASN.1 data
structures. An attacker could exploit this with specially crafted ASN.1
data and cause applications using Libtasn1 to crash, resulting in a denial
of service. (CVE-2014-3467)
It was discovered that Libtasn1 incorrectly handled negative bit lengths.
An attacker could exploit this with specially crafted ASN.1 data and cause
applications using Libtasn1 to crash, resulting in a denial of service, or
possibly execute arbitrary code. (CVE-2014-3468)
It was discovered that Libtasn1 incorrectly handled certain ASN.1 data. An
attacker could exploit this with specially crafted ASN.1 da
Red Hat
libtasn1: asn1_get_bit_der() can return negative bit length
vendor_redhat·2014-05-25·CVSS 7.5
CVE-2014-3468 [HIGH] CWE-392 libtasn1: asn1_get_bit_der() can return negative bit length
libtasn1: asn1_get_bit_der() can return negative bit length
The asn1_get_bit_der function in GNU Libtasn1 before 3.6 does not properly report an error when a negative bit length is identified, which allows context-dependent attackers to cause out-of-bounds access via crafted ASN.1 data.
Package: gnutls (Red Hat Enterprise Linux 4) - Will not fix
Package: mingw32-gnutls (Red Hat Enterprise Linux 6) - Will not fix
Debian
CVE-2014-3468: libtasn1-6 - The asn1_get_bit_der function in GNU Libtasn1 before 3.6 does not properly repor...
vendor_debian·2014·CVSS 7.5
CVE-2014-3468 [HIGH] CVE-2014-3468: libtasn1-6 - The asn1_get_bit_der function in GNU Libtasn1 before 3.6 does not properly repor...
The asn1_get_bit_der function in GNU Libtasn1 before 3.6 does not properly report an error when a negative bit length is identified, which allows context-dependent attackers to cause out-of-bounds access via crafted ASN.1 data.
Scope: local
bookworm: resolved (fixed in 3.6-1)
bullseye: resolved (fixed in 3.6-1)
forky: resolved (fixed in 3.6-1)
sid: resolved (fixed in 3.6-1)
trixie: resolved (fixed in 3.6-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-3467 CVE-2014-3469 CVE-2014-3468 libtasn1: various flaws [fedora-all]
bugzilla·2014-05-30·CVSS 5.0
CVE-2014-3467 [MEDIUM] CVE-2014-3467 CVE-2014-3469 CVE-2014-3468 libtasn1: various flaws [fedora-all]
CVE-2014-3467 CVE-2014-3469 CVE-2014-3468 libtasn1: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
NOTE: this issue affects multiple
Bugzilla
CVE-2014-3467 CVE-2014-3469 CVE-2014-3468 mingw32-gnutls: various flaws [epel-5]
bugzilla·2014-05-30·CVSS 5.0
CVE-2014-3467 [MEDIUM] CVE-2014-3467 CVE-2014-3469 CVE-2014-3468 mingw32-gnutls: various flaws [epel-5]
CVE-2014-3467 CVE-2014-3469 CVE-2014-3468 mingw32-gnutls: various flaws [epel-5]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
epel-5 tracking bug for mi
Bugzilla
CVE-2014-3467 CVE-2014-3469 CVE-2014-3468 mingw-libtasn1: various flaws [fedora-all]
bugzilla·2014-05-30·CVSS 5.0
CVE-2014-3467 [MEDIUM] CVE-2014-3467 CVE-2014-3469 CVE-2014-3468 mingw-libtasn1: various flaws [fedora-all]
CVE-2014-3467 CVE-2014-3469 CVE-2014-3468 mingw-libtasn1: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
NOTE: this issue affects mu
Bugzilla
CVE-2014-3468 libtasn1: asn1_get_bit_der() can return negative bit length
bugzilla·2014-05-28·CVSS 7.5
CVE-2014-3468 [HIGH] CVE-2014-3468 libtasn1: asn1_get_bit_der() can return negative bit length
CVE-2014-3468 libtasn1: asn1_get_bit_der() can return negative bit length
It was discovered that libtasn1 library function asn1_get_bit_der() could incorrectly report negative bit length of the value read from ASN.1 input. This could possibly lead to an out of bounds access in an application using libtasn1, for example in case if application tried to terminate read value with NUL byte.
The following upstream commit corrects the issue and causes the function to report error rather than return negative length value:
http://git.savannah.gnu.org/cgit/libtasn1.git/commit/?id=1c3ccb3e040bf13e342ee60bc23b21b97b11923f
Discussion:
Acknowledgment:
Red Hat would like to thank GnuTLS upstream for reporting this issue.
---
Fixed upstream in libtasn1 3.6:
http://lists.gnu.org/archive/html/help-li
http://advisories.mageia.org/MGASA-2014-0247.htmlhttp://git.savannah.gnu.org/cgit/libtasn1.git/commit/?id=1c3ccb3e040bf13e342ee60bc23b21b97b11923fhttp://linux.oracle.com/errata/ELSA-2014-0594.htmlhttp://linux.oracle.com/errata/ELSA-2014-0596.htmlhttp://lists.gnu.org/archive/html/help-libtasn1/2014-05/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-06/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-06/msg00015.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0594.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0596.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0687.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0815.htmlhttp://secunia.com/advisories/58591http://secunia.com/advisories/58614http://secunia.com/advisories/59021http://secunia.com/advisories/59057http://secunia.com/advisories/59408http://secunia.com/advisories/60320http://secunia.com/advisories/60415http://secunia.com/advisories/61888http://support.f5.com/kb/en-us/solutions/public/15000/400/sol15423.htmlhttp://www.debian.org/security/2014/dsa-3056http://www.mandriva.com/security/advisories?name=MDVSA-2015:116http://www.novell.com/support/kb/doc.php?id=7015302http://www.novell.com/support/kb/doc.php?id=7015303https://bugzilla.redhat.com/show_bug.cgi?id=1102323http://advisories.mageia.org/MGASA-2014-0247.htmlhttp://git.savannah.gnu.org/cgit/libtasn1.git/commit/?id=1c3ccb3e040bf13e342ee60bc23b21b97b11923fhttp://linux.oracle.com/errata/ELSA-2014-0594.htmlhttp://linux.oracle.com/errata/ELSA-2014-0596.htmlhttp://lists.gnu.org/archive/html/help-libtasn1/2014-05/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-06/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-06/msg00015.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0594.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0596.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0687.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0815.htmlhttp://secunia.com/advisories/58591http://secunia.com/advisories/58614http://secunia.com/advisories/59021http://secunia.com/advisories/59057http://secunia.com/advisories/59408http://secunia.com/advisories/60320http://secunia.com/advisories/60415http://secunia.com/advisories/61888http://support.f5.com/kb/en-us/solutions/public/15000/400/sol15423.htmlhttp://www.debian.org/security/2014/dsa-3056http://www.mandriva.com/security/advisories?name=MDVSA-2015:116http://www.novell.com/support/kb/doc.php?id=7015302http://www.novell.com/support/kb/doc.php?id=7015303https://bugzilla.redhat.com/show_bug.cgi?id=1102323
2014-06-05
Published