- libtasn1 buffer overflow
Published Feb 10, 2006
7.5
HIGHCVSS 2.0
EPSS 3.89%
Description
Tiny ASN.1 Library (libtasn1) before 0.2.18, as used by (1) GnuTLS 1.2.x before 1.2.10 and 1.3.x before 1.3.4, and (2) GNU Shishi, allows attackers to crash the DER decoder and possibly execute arbitrary code via "out-of-bounds access" caused by invalid input, as demonstrated by the ProtoVer SSL test suite.
Affected products
No data.
- 0.1.0
- 0.1.1
- 0.1.2
- 0.2.0
- 0.2.1
- 0.2.2
- 0.2.3
- 0.2.4
- 0.2.5
- 0.2.6
- 0.2.7
- 0.2.8
- 0.2.9
- 0.2.10
- 0.2.11
- 0.2.12
- 0.2.13
- 0.2.14
- 0.2.15
- 0.2.16
- 0.2.17
No data.
Red Hat Enterprise Linux 4
gnutls-0:1.0.20-3.2.2
Fixed · RHSA-2006:0207
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 4 | gnutls-0:1.0.20-3.2.2 | Fixed | RHSA-2006:0207 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (12 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 3.89% (0.03892) | 89.92th | v5 (v2026.06.15) |
| Jun 15, 2026 | 3.51% (0.03507) | 87.64th | v5 (v2026.06.15) |
| Mar 30, 2025 | 4.39% (0.04390) | 87.93th | v4 (v2025.03.14) |
| Mar 29, 2025 | 8.33% (0.08330) | 86.87th | v4 (v2025.03.14) |
| Mar 17, 2025 | 4.39% (0.04390) | 88.23th | v4 (v2025.03.14) |
| Dec 12, 2024 | 3.02% (0.03019) | 91.30th | v3 (v2023.03.01) |
| Mar 7, 2023 | 3.02% (0.03019) | 89.38th | v3 (v2023.03.01) |
| Mar 6, 2023 | 4.42% (0.04421) | 88.21th | v2 (v2022.01.01) |
| Feb 13, 2023 | 4.42% (0.04421) | 87.82th | v2 (v2022.01.01) |
| Feb 3, 2023 | 2.69% (0.02686) | 82.44th | v2 (v2022.01.01) |
| Apr 1, 2022 | 4.42% (0.04421) | 87.03th | v2 (v2022.01.01) |
| Feb 4, 2022 | 4.42% (0.04421) | 70.83th | v2 (v2022.01.01) |
No CWE recorded.
References (35)
- http://josefsson.org/cgi-bin/viewcvs.cgi/gnutls/tests/certder.c?view=markup x_refsource_MISC
- http://josefsson.org/cgi-bin/viewcvs.cgi/libtasn1/NEWS?root=gnupg-mirror&view=markup x_refsource_CONFIRM
- http://josefsson.org/gnutls/releases/libtasn1/libtasn1-0.2.18-from-0.2.17.patch x_refsource_MISC
- http://lists.gnupg.org/pipermail/gnutls-dev/2006-February/001058.html mailing-listx_refsource_MLIST
- http://lists.gnupg.org/pipermail/gnutls-dev/2006-February/001059.html mailing-listx_refsource_MLIST
- http://lists.gnupg.org/pipermail/gnutls-dev/2006-February/001060.html mailing-listx_refsource_MLIST
- http://rhn.redhat.com/errata/RHSA-2006-0207.html vendor-advisoryx_refsource_REDHAT
- http://secunia.com/advisories/18794 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/18815 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/18830 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/18832 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/18898 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/18918 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/19080 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/19092 third-party-advisoryx_refsource_SECUNIA
- http://securityreason.com/securityalert/446 third-party-advisoryx_refsource_SREASON
- http://securitytracker.com/id?1015612 vdb-entryx_refsource_SECTRACK
- http://www.debian.org/security/2006/dsa-985 vendor-advisoryx_refsource_DEBIAN
- http://www.debian.org/security/2006/dsa-986 vendor-advisoryx_refsource_DEBIAN
- http://www.gentoo.org/security/en/glsa/glsa-200602-08.xml vendor-advisoryx_refsource_GENTOO
- http://www.gleg.net/protover_ssl.shtml x_refsource_MISC
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:039 vendor-advisoryx_refsource_MANDRIVA
- http://www.osvdb.org/23054 vdb-entryx_refsource_OSVDB
- http://www.redhat.com/archives/fedora-announce-list/2006-February/msg00043.html vendor-advisoryx_refsource_FEDORA
- http://www.securityfocus.com/archive/1/424538/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/bid/16568 vdb-entryx_refsource_BID
- http://www.trustix.org/errata/2006/0008 vendor-advisoryx_refsource_TRUSTIX
- http://www.vupen.com/english/advisories/2006/0496 vdb-entryx_refsource_VUPEN
- https://access.redhat.com/security/cve/CVE-2006-0645 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=184097 Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24606 vdb-entryx_refsource_XF
- https://nvd.nist.gov/vuln/detail/CVE-2006-0645
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10540 vdb-entrysignaturex_refsource_OVAL
- https://usn.ubuntu.com/251-1/ vendor-advisoryx_refsource_UBUNTU
- https://www.cve.org/CVERecord?id=CVE-2006-0645
Change history (0)
No recorded changes yet.