CVE-2014-3469
published 2014-06-05CVE-2014-3469: The (1) asn1_read_value_type and (2) asn1_read_value functions in GNU Libtasn1 before 3.6 allows context-dependent attackers to cause a denial of service (NULL…
PriorityP423medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
3.82%
88.9th percentile
The (1) asn1_read_value_type and (2) asn1_read_value functions in GNU Libtasn1 before 3.6 allows context-dependent attackers to cause a denial of service (NULL pointer dereference and crash) via a NULL value in an ivalue argument.
Affected
33 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | libtasn1-6 | < libtasn1-6 3.6-1 (bookworm) | libtasn1-6 3.6-1 (bookworm) |
| gnu | gnutls | < 3.5.7 | 3.5.7 |
| gnu | libtasn1 | < 3.6 | 3.6 |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Libtasn1 vulnerabilities
vendor_ubuntu·2014-07-22·CVSS 5.0
CVE-2014-3467 [MEDIUM] Libtasn1 vulnerabilities
Title: Libtasn1 vulnerabilities
Summary: Libtasn1 could be made to crash or run programs as your login if it
processed specially crafted data.
It was discovered that Libtasn1 incorrectly handled certain ASN.1 data
structures. An attacker could exploit this with specially crafted ASN.1
data and cause applications using Libtasn1 to crash, resulting in a denial
of service. (CVE-2014-3467)
It was discovered that Libtasn1 incorrectly handled negative bit lengths.
An attacker could exploit this with specially crafted ASN.1 data and cause
applications using Libtasn1 to crash, resulting in a denial of service, or
possibly execute arbitrary code. (CVE-2014-3468)
It was discovered that Libtasn1 incorrectly handled certain ASN.1 data. An
attacker could exploit this with specially crafted ASN.1 da
Red Hat
libtasn1: asn1_read_value_type() NULL pointer dereference
vendor_redhat·2014-05-25·CVSS 5.0
CVE-2014-3469 [MEDIUM] CWE-476 libtasn1: asn1_read_value_type() NULL pointer dereference
libtasn1: asn1_read_value_type() NULL pointer dereference
The (1) asn1_read_value_type and (2) asn1_read_value functions in GNU Libtasn1 before 3.6 allows context-dependent attackers to cause a denial of service (NULL pointer dereference and crash) via a NULL value in an ivalue argument.
Package: gnutls (Red Hat Enterprise Linux 4) - Will not fix
Package: mingw32-gnutls (Red Hat Enterprise Linux 6) - Will not fix
Debian
CVE-2014-3469: libtasn1-6 - The (1) asn1_read_value_type and (2) asn1_read_value functions in GNU Libtasn1 b...
vendor_debian·2014·CVSS 5.0
CVE-2014-3469 [MEDIUM] CVE-2014-3469: libtasn1-6 - The (1) asn1_read_value_type and (2) asn1_read_value functions in GNU Libtasn1 b...
The (1) asn1_read_value_type and (2) asn1_read_value functions in GNU Libtasn1 before 3.6 allows context-dependent attackers to cause a denial of service (NULL pointer dereference and crash) via a NULL value in an ivalue argument.
Scope: local
bookworm: resolved (fixed in 3.6-1)
bullseye: resolved (fixed in 3.6-1)
forky: resolved (fixed in 3.6-1)
sid: resolved (fixed in 3.6-1)
trixie: resolved (fixed in 3.6-1)
GHSA
GHSA-52vj-cjhg-wpwv: The (1) asn1_read_value_type and (2) asn1_read_value functions in GNU Libtasn1 before 3
ghsa_unreviewed·2022-05-13
CVE-2014-3469 [MEDIUM] CWE-476 GHSA-52vj-cjhg-wpwv: The (1) asn1_read_value_type and (2) asn1_read_value functions in GNU Libtasn1 before 3
The (1) asn1_read_value_type and (2) asn1_read_value functions in GNU Libtasn1 before 3.6 allows context-dependent attackers to cause a denial of service (NULL pointer dereference and crash) via a NULL value in an ivalue argument.
OSV
libtasn1-3, libtasn1-6 vulnerabilities
osv·2014-07-22·CVSS 5.0
CVE-2014-3467 [MEDIUM] libtasn1-3, libtasn1-6 vulnerabilities
libtasn1-3, libtasn1-6 vulnerabilities
It was discovered that Libtasn1 incorrectly handled certain ASN.1 data
structures. An attacker could exploit this with specially crafted ASN.1
data and cause applications using Libtasn1 to crash, resulting in a denial
of service. (CVE-2014-3467)
It was discovered that Libtasn1 incorrectly handled negative bit lengths.
An attacker could exploit this with specially crafted ASN.1 data and cause
applications using Libtasn1 to crash, resulting in a denial of service, or
possibly execute arbitrary code. (CVE-2014-3468)
It was discovered that Libtasn1 incorrectly handled certain ASN.1 data. An
attacker could exploit this with specially crafted ASN.1 data and cause
applications using Libtasn1 to crash, resulting in a denial of service.
(CVE-2014-3469)
OSV
CVE-2014-3469: The (1) asn1_read_value_type and (2) asn1_read_value functions in GNU Libtasn1 before 3
osv·2014-06-05·CVSS 5.0
CVE-2014-3469 [MEDIUM] CVE-2014-3469: The (1) asn1_read_value_type and (2) asn1_read_value functions in GNU Libtasn1 before 3
The (1) asn1_read_value_type and (2) asn1_read_value functions in GNU Libtasn1 before 3.6 allows context-dependent attackers to cause a denial of service (NULL pointer dereference and crash) via a NULL value in an ivalue argument.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-3467 CVE-2014-3469 CVE-2014-3468 libtasn1: various flaws [fedora-all]
bugzilla·2014-05-30·CVSS 5.0
CVE-2014-3467 [MEDIUM] CVE-2014-3467 CVE-2014-3469 CVE-2014-3468 libtasn1: various flaws [fedora-all]
CVE-2014-3467 CVE-2014-3469 CVE-2014-3468 libtasn1: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
NOTE: this issue affects multiple
Bugzilla
CVE-2014-3467 CVE-2014-3469 CVE-2014-3468 mingw32-gnutls: various flaws [epel-5]
bugzilla·2014-05-30·CVSS 5.0
CVE-2014-3467 [MEDIUM] CVE-2014-3467 CVE-2014-3469 CVE-2014-3468 mingw32-gnutls: various flaws [epel-5]
CVE-2014-3467 CVE-2014-3469 CVE-2014-3468 mingw32-gnutls: various flaws [epel-5]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
epel-5 tracking bug for mi
Bugzilla
CVE-2014-3467 CVE-2014-3469 CVE-2014-3468 mingw-libtasn1: various flaws [fedora-all]
bugzilla·2014-05-30·CVSS 5.0
CVE-2014-3467 [MEDIUM] CVE-2014-3467 CVE-2014-3469 CVE-2014-3468 mingw-libtasn1: various flaws [fedora-all]
CVE-2014-3467 CVE-2014-3469 CVE-2014-3468 mingw-libtasn1: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
NOTE: this issue affects mu
Bugzilla
CVE-2014-3469 libtasn1: asn1_read_value_type() NULL pointer dereference
bugzilla·2014-05-28·CVSS 5.0
CVE-2014-3469 [MEDIUM] CVE-2014-3469 libtasn1: asn1_read_value_type() NULL pointer dereference
CVE-2014-3469 libtasn1: asn1_read_value_type() NULL pointer dereference
A NULL pointer dereference flaw was found in libtasn1's asn1_read_value_type() / asn1_read_value() function. If an application called the function with a NULL value for an ivalue argument to determine the amount of memory needed to store data to be read from the ASN.1 input, libtasn1 could incorrectly attempt to dereference the NULL pointer, causing an application using the library to crash.
The libtasn1 library is used by the GnuTLS library to parse X.509 certificates. The gnutls packages in Red Hat Enterprise Linux 5 and earlier use bundled libtasn1, packages in Red Hat Enterprise Linux 6 and later depend on the library provided by a separate libtasn1 package.
Upstream commits:
http://git.savannah.gnu.org/cgit/lib
http://advisories.mageia.org/MGASA-2014-0247.htmlhttp://linux.oracle.com/errata/ELSA-2014-0594.htmlhttp://linux.oracle.com/errata/ELSA-2014-0596.htmlhttp://lists.gnu.org/archive/html/help-libtasn1/2014-05/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-06/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-06/msg00015.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0594.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0596.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0687.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0815.htmlhttp://secunia.com/advisories/58591http://secunia.com/advisories/58614http://secunia.com/advisories/59021http://secunia.com/advisories/59057http://secunia.com/advisories/59408http://secunia.com/advisories/60320http://secunia.com/advisories/60415http://secunia.com/advisories/61888http://www.debian.org/security/2014/dsa-3056http://www.mandriva.com/security/advisories?name=MDVSA-2015:116http://www.novell.com/support/kb/doc.php?id=7015302http://www.novell.com/support/kb/doc.php?id=7015303https://bugzilla.redhat.com/show_bug.cgi?id=1102329http://advisories.mageia.org/MGASA-2014-0247.htmlhttp://linux.oracle.com/errata/ELSA-2014-0594.htmlhttp://linux.oracle.com/errata/ELSA-2014-0596.htmlhttp://lists.gnu.org/archive/html/help-libtasn1/2014-05/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-06/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-06/msg00015.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0594.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0596.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0687.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0815.htmlhttp://secunia.com/advisories/58591http://secunia.com/advisories/58614http://secunia.com/advisories/59021http://secunia.com/advisories/59057http://secunia.com/advisories/59408http://secunia.com/advisories/60320http://secunia.com/advisories/60415http://secunia.com/advisories/61888http://www.debian.org/security/2014/dsa-3056http://www.mandriva.com/security/advisories?name=MDVSA-2015:116http://www.novell.com/support/kb/doc.php?id=7015302http://www.novell.com/support/kb/doc.php?id=7015303https://bugzilla.redhat.com/show_bug.cgi?id=1102329
2014-06-05
Published