libtasn1-3 vulnerability

Related Vulnerabilities: CVE-2012-1569  

Libtasn1 could be made to crash or run programs as your login if it received specially crafted input.

Matthew Hall discovered that Libtasn1 incorrectly handled certain large values. An attacker could exploit this with a specially crafted ASN.1 structure and cause a denial of service, or possibly execute arbitrary code.

2 May 2012

libtasn1-3 vulnerability

A security issue affects these releases of Ubuntu and its derivatives:

  • Ubuntu 12.04 LTS
  • Ubuntu 11.10
  • Ubuntu 11.04
  • Ubuntu 10.04 LTS
  • Ubuntu 8.04 LTS

Summary

Libtasn1 could be made to crash or run programs as your login if it received specially crafted input.

Software Description

  • libtasn1-3 - Library to manage ASN.1 structures

Details

Matthew Hall discovered that Libtasn1 incorrectly handled certain large values. An attacker could exploit this with a specially crafted ASN.1 structure and cause a denial of service, or possibly execute arbitrary code.

Update instructions

The problem can be corrected by updating your system to the following package versions:

Ubuntu 12.04 LTS
libtasn1-3 - 2.10-1ubuntu1.1
Ubuntu 11.10
libtasn1-3 - 2.9-4ubuntu0.1
Ubuntu 11.04
libtasn1-3 - 2.7-1ubuntu1.1
Ubuntu 10.04 LTS
libtasn1-3 - 2.4-1ubuntu0.1
Ubuntu 8.04 LTS
libtasn1-3 - 1.1-1ubuntu0.1

To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades.

In general, a standard system update will make all the necessary changes.

References