7.5
CVSSv2

CVE-2014-3468

Published: 05/06/2014 Updated: 16/11/2020
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The asn1_get_bit_der function in GNU Libtasn1 prior to 3.6 does not properly report an error when a negative bit length is identified, which allows context-dependent malicious users to cause out-of-bounds access via crafted ASN.1 data.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

gnu gnutls

gnu libtasn1

redhat virtualization 6.0

debian debian linux 7.0

redhat enterprise linux desktop 5.0

redhat enterprise linux desktop 6.0

redhat enterprise linux desktop 7.0

redhat enterprise linux eus 6.5

redhat enterprise linux eus 7.3

redhat enterprise linux eus 7.4

redhat enterprise linux eus 7.5

redhat enterprise linux eus 7.6

redhat enterprise linux eus 7.7

redhat enterprise linux server 5.0

redhat enterprise linux server 6.0

redhat enterprise linux server 7.0

redhat enterprise linux server aus 6.5

redhat enterprise linux server aus 7.3

redhat enterprise linux server aus 7.4

redhat enterprise linux server aus 7.6

redhat enterprise linux server aus 7.7

redhat enterprise linux server tus 6.5

redhat enterprise linux server tus 7.3

redhat enterprise linux server tus 7.6

redhat enterprise linux server tus 7.7

redhat enterprise linux workstation 5.0

redhat enterprise linux workstation 6.0

redhat enterprise linux workstation 7.0

suse linux enterprise desktop 11

suse linux enterprise high availability extension 11

suse linux enterprise server 11

suse linux enterprise software development kit 11

f5 arx_firmware

Vendor Advisories

Libtasn1 could be made to crash or run programs as your login if it processed specially crafted data ...
Several vulnerabilities were discovered in libtasn1-3, a library that manages ASN1 (Abstract Syntax Notation One) structures An attacker could use those to cause a denial-of-service via out-of-bounds access or NULL pointer dereference For the stable distribution (wheezy), these problems have been fixed in version 213-2+deb7u1 We recommend that ...
It was discovered that the asn1_get_bit_der() function of the libtasn1 library incorrectly reported the length of ASN1-encoded data Specially crafted ASN1 input could cause an application using libtasn1 to perform an out-of-bounds access operation, causing the application to crash or, possibly, execute arbitrary code (CVE-2014-3468) Multiple in ...
The asn1_get_bit_der function in GNU Libtasn1 before 36 does not properly report an error when a negative bit length is identified, which allows context-dependent attackers to cause out-of-bounds access via crafted ASN1 data ...