The (1) asn1_read_value_type and (2) asn1_read_value functions in GNU Libtasn1 before 3.6 allows context-dependent attackers to cause a denial of service (NULL pointer dereference and crash) via a NULL value in an ivalue argument.
A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Gnutls | Gnu | * | 3.5.7 (excluding) |
Libtasn1 | Gnu | * | 3.6 (excluding) |
Red Hat Enterprise Linux 5 | RedHat | gnutls-0:1.4.1-16.el5_10 | * |
Red Hat Enterprise Linux 6 | RedHat | libtasn1-0:2.3-6.el6_5 | * |
Red Hat Enterprise Linux 7 | RedHat | libtasn1-0:3.3-5.el7_0 | * |
RHEV 3.X Hypervisor and Agents for RHEL-6 | RedHat | rhev-hypervisor6-0:6.5-20140624.0.el6ev | * |
Libtasn1-3 | Ubuntu | lucid | * |
Libtasn1-3 | Ubuntu | precise | * |
Libtasn1-3 | Ubuntu | saucy | * |
Libtasn1-6 | Ubuntu | saucy | * |
Libtasn1-6 | Ubuntu | trusty | * |
Libtasn1-6 | Ubuntu | upstream | * |