The _asn1_extract_der_octet function in lib/decoding.c in GNU Libtasn1 before 4.8, when used without the ASN1_DECODE_FLAG_STRICT_DER flag, allows remote attackers to cause a denial of service (infinite recursion) via a crafted certificate.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Ubuntu_linux | Canonical | 12.04 (including) | 12.04 (including) |
Ubuntu_linux | Canonical | 14.04 (including) | 14.04 (including) |
Ubuntu_linux | Canonical | 15.10 (including) | 15.10 (including) |
Ubuntu_linux | Canonical | 16.04 (including) | 16.04 (including) |
Libtasn1-3 | Ubuntu | precise | * |
Libtasn1-3 | Ubuntu | upstream | * |
Libtasn1-6 | Ubuntu | trusty | * |
Libtasn1-6 | Ubuntu | upstream | * |
Libtasn1-6 | Ubuntu | vivid/stable-phone-overlay | * |
Libtasn1-6 | Ubuntu | vivid/ubuntu-core | * |
Libtasn1-6 | Ubuntu | wily | * |
Libtasn1-6 | Ubuntu | xenial | * |