The _asn1_check_identifier function in GNU Libtasn1 through 4.12 causes a NULL pointer dereference and crash when reading crafted input that triggers assignment of a NULL value within an asn1_node structure. It may lead to a remote denial of service attack.
A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Libtasn1 | Gnu | * | 4.12 (including) |
Libtasn1-3 | Ubuntu | precise/esm | * |
Libtasn1-6 | Ubuntu | trusty | * |
Libtasn1-6 | Ubuntu | vivid/ubuntu-core | * |
Libtasn1-6 | Ubuntu | xenial | * |
Libtasn1-6 | Ubuntu | yakkety | * |
Libtasn1-6 | Ubuntu | zesty | * |