CVE Vulnerabilities

CVE-2006-0645

Published: Feb 10, 2006 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
UNTRIAGED

Tiny ASN.1 Library (libtasn1) before 0.2.18, as used by (1) GnuTLS 1.2.x before 1.2.10 and 1.3.x before 1.3.4, and (2) GNU Shishi, allows attackers to crash the DER decoder and possibly execute arbitrary code via out-of-bounds access caused by invalid input, as demonstrated by the ProtoVer SSL test suite.

Affected Software

Name Vendor Start Version End Version
Libtasn1 Free_software_foundation_inc. 0.1.0 (including) 0.1.0 (including)
Libtasn1 Free_software_foundation_inc. 0.1.1 (including) 0.1.1 (including)
Libtasn1 Free_software_foundation_inc. 0.1.2 (including) 0.1.2 (including)
Libtasn1 Free_software_foundation_inc. 0.2.0 (including) 0.2.0 (including)
Libtasn1 Free_software_foundation_inc. 0.2.1 (including) 0.2.1 (including)
Libtasn1 Free_software_foundation_inc. 0.2.2 (including) 0.2.2 (including)
Libtasn1 Free_software_foundation_inc. 0.2.3 (including) 0.2.3 (including)
Libtasn1 Free_software_foundation_inc. 0.2.4 (including) 0.2.4 (including)
Libtasn1 Free_software_foundation_inc. 0.2.5 (including) 0.2.5 (including)
Libtasn1 Free_software_foundation_inc. 0.2.6 (including) 0.2.6 (including)
Libtasn1 Free_software_foundation_inc. 0.2.7 (including) 0.2.7 (including)
Libtasn1 Free_software_foundation_inc. 0.2.8 (including) 0.2.8 (including)
Libtasn1 Free_software_foundation_inc. 0.2.9 (including) 0.2.9 (including)
Libtasn1 Free_software_foundation_inc. 0.2.10 (including) 0.2.10 (including)
Libtasn1 Free_software_foundation_inc. 0.2.11 (including) 0.2.11 (including)
Libtasn1 Free_software_foundation_inc. 0.2.12 (including) 0.2.12 (including)
Libtasn1 Free_software_foundation_inc. 0.2.13 (including) 0.2.13 (including)
Libtasn1 Free_software_foundation_inc. 0.2.14 (including) 0.2.14 (including)
Libtasn1 Free_software_foundation_inc. 0.2.15 (including) 0.2.15 (including)
Libtasn1 Free_software_foundation_inc. 0.2.16 (including) 0.2.16 (including)
Libtasn1 Free_software_foundation_inc. 0.2.17 (including) 0.2.17 (including)
Red Hat Enterprise Linux 4 RedHat gnutls-0:1.0.20-3.2.2 *
Libtasn1-2 Ubuntu dapper *
Libtasn1-2 Ubuntu edgy *

References