Tiny ASN.1 Library (libtasn1) before 0.2.18, as used by (1) GnuTLS 1.2.x before 1.2.10 and 1.3.x before 1.3.4, and (2) GNU Shishi, allows attackers to crash the DER decoder and possibly execute arbitrary code via "out-of-bounds access" caused by invalid input, as demonstrated by the ProtoVer SSL test suite.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-985-1 | New libtasn1-2 packages fix arbitrary code execution |
Debian DSA |
DSA-986-1 | New gnutls11 packages fix arbitrary code execution |
EUVD |
EUVD-2006-0652 | Tiny ASN.1 Library (libtasn1) before 0.2.18, as used by (1) GnuTLS 1.2.x before 1.2.10 and 1.3.x before 1.3.4, and (2) GNU Shishi, allows attackers to crash the DER decoder and possibly execute arbitrary code via "out-of-bounds access" caused by invalid input, as demonstrated by the ProtoVer SSL test suite. |
Ubuntu USN |
USN-251-1 | libtasn vulnerability |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-07T16:41:29.006Z
Reserved: 2006-02-10T00:00:00
Link: CVE-2006-0645
No data.
Status : Deferred
Published: 2006-02-10T18:06:00.000
Modified: 2025-04-03T01:03:51.193
Link: CVE-2006-0645
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA
EUVD
Ubuntu USN