Skip to content

CVE-2014-3468

The asn1_get_bit_der function in GNU Libtasn1 before 3.6 does not properly report an error when a negative bit length is identified, which allows context-dependent attackers to cause out-of-bounds access via crafted ASN.1 data.

Ver en NVD

Severidad

N/A

EPSS

Probabilidad de explotación (próx. 30 días): 0.1074 (10.7%)
Percentil: 93.4%
EPSS: 2026-05-06

Afecta

gnu:gnutlsgnu:libtasn1redhat:virtualizationdebian:debian_linuxredhat:enterprise_linux_desktopredhat:enterprise_linux_eusredhat:enterprise_linux_serverredhat:enterprise_linux_server_ausredhat:enterprise_linux_server_tusredhat:enterprise_linux_workstationsuse:linux_enterprise_desktopsuse:linux_enterprise_high_availability_extensionsuse:linux_enterprise_serversuse:linux_enterprise_software_development_kitf5:arx_firmwaref5:arx

Descripción técnica

The asn1_get_bit_der function in GNU Libtasn1 before 3.6 does not properly report an error when a negative bit length is identified, which allows context-dependent attackers to cause out-of-bounds access via crafted ASN.1 data.

Publicada: 5/6/2014, 20:55:06
Última modificación: 6/5/2026, 22:30:45

Referencias

InicioEventosBlogRecursosEquipo