CVE-2014-3468
7.5
Vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploitability: 10.0 / Impact: 6.4
Source: NVD
Description
The asn1_get_bit_der function in GNU Libtasn1 before 3.6 does not properly report an error when a negative bit length is identified, which allows context-dependent attackers to cause out-of-bounds access via crafted ASN.1 data.
Affected (36)
Products: Gnu: Gnutls, Libtasn1 · Redhat: Enterprise Linux Desktop, Enterprise Linux Eus, Enterprise Linux Server, Enterprise Linux Server Aus, Enterprise Linux Server Tus, Enterprise Linux Workstation, Virtualization · Suse: Linux Enterprise Desktop, Linux Enterprise High Availability Extension, Linux Enterprise Server, Linux Enterprise Software Development Kit · +2 more
Show all products
Gnu: Gnutls, Libtasn1 · Redhat: Enterprise Linux Desktop, Enterprise Linux Eus, Enterprise Linux Server, Enterprise Linux Server Aus, Enterprise Linux Server Tus, Enterprise Linux Workstation, Virtualization · Suse: Linux Enterprise Desktop, Linux Enterprise High Availability Extension, Linux Enterprise Server, Linux Enterprise Software Development Kit · Debian: Debian Linux · F5: Arx Firmware
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 5.0 | |
| Version 6.5 | |
| Version 5.0 | |
| Version 6.5 | |
| Version 6.5 | |
| Version 5.0 | |
| Version 6.0 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 11 sp3 | |
| Version 11 sp3 | |
| Version 11 sp1 | |
| Version 11 sp3 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version 7.0 |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| From 6.0.0 to 6.4.0 |
| Running on/with | Platform Versions |
|---|---|
F5 Arx | All versions |
References (50)
Source: secalert@redhat.com
PatchVendor Advisory
Source: secalert@redhat.com
Mailing ListPatchVendor Advisory
Source: secalert@redhat.com
Mailing ListThird Party Advisory
Source: secalert@redhat.com
Mailing ListThird Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Issue TrackingThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListPatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingThird Party Advisory
Timeline
No history available yet.