Back

MEDIUM

libtasn1: DER decoding buffer overflow (GNUTLS-SA-2012-3, MU-201202-02)

Published Mar 26, 2012

Description

The asn1_get_length_der function in decoding.c in GNU Libtasn1 before 2.12, as used in GnuTLS before 3.0.16 and other products, does not properly handle certain large length values, which allows remote attackers to cause a denial of service (heap memory corruption and application crash) or possibly have unspecified other impact via a crafted ASN.1 structure.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (36)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Mar 26, 2012
Updated Aug 6, 2024
Reserved Mar 12, 2012
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Important
Public date Mar 19, 2012