CVE-2014-3468
Publication date 5 June 2014
Last updated 24 July 2024
Ubuntu priority
The asn1_get_bit_der function in GNU Libtasn1 before 3.6 does not properly report an error when a negative bit length is identified, which allows context-dependent attackers to cause out-of-bounds access via crafted ASN.1 data.
Status
Package | Ubuntu Release | Status |
---|---|---|
libtasn1-3 | 14.04 LTS trusty | Not in release |
libtasn1-6 | 14.04 LTS trusty |
Fixed 3.4-3ubuntu0.1
|
References
Related Ubuntu Security Notices (USN)
- USN-2294-1
- Libtasn1 vulnerabilities
- 22 July 2014