384
VMScore

CVE-2016-4008

Published: 05/05/2016 Updated: 07/11/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.9 | Impact Score: 3.6 | Exploitability Score: 2.2
VMScore: 384
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

The _asn1_extract_der_octet function in lib/decoding.c in GNU Libtasn1 prior to 4.8, when used without the ASN1_DECODE_FLAG_STRICT_DER flag, allows remote malicious users to cause a denial of service (infinite recursion) via a crafted certificate.

Vulnerable Product Search on Vulmon Subscribe to Product

canonical ubuntu linux 12.04

canonical ubuntu linux 16.04

canonical ubuntu linux 15.10

canonical ubuntu linux 14.04

opensuse opensuse 13.2

gnu libtasn1

fedoraproject fedora 22

fedoraproject fedora 24

fedoraproject fedora 23

Vendor Advisories

Libtasn1 could be made to hang if it processed specially crafted data ...
Libtasn1 could be made to hang if it processed specially crafted data ...
Pascal Cuoq and Miod Vallat discovered that Libtasn1, a library to manage ASN1 structures, does not correctly handle certain malformed DER certificates A remote attacker can take advantage of this flaw to cause an application using the Libtasn1 library to hang, resulting in a denial of service For the stable distribution (jessie), this problem h ...
The _asn1_extract_der_octet function in lib/decodingc in GNU Libtasn1 before 48, when used without the ASN1_DECODE_FLAG_STRICT_DER flag, allows remote attackers to cause a denial of service (infinite recursion) via a crafted certificate ...