CVE-2014-3468
Publication date 5 June 2014
Last updated 24 July 2024
Ubuntu priority
Description
The asn1_get_bit_der function in GNU Libtasn1 before 3.6 does not properly report an error when a negative bit length is identified, which allows context-dependent attackers to cause out-of-bounds access via crafted ASN.1 data.
Status
| Package | Ubuntu Release | Status | 
|---|---|---|
| libtasn1-3 | 14.04 LTS trusty | Not in release | 
| libtasn1-6 | 14.04 LTS trusty | 
                              
                               
                                Fixed 3.4-3ubuntu0.1 
                                
                               
                             |      
                          
                            
                          
                        
                      
References
Related Ubuntu Security Notices (USN)
- USN-2294-1
 - Libtasn1 vulnerabilities
 - 22 July 2014