Two errors in the "asn1_find_node()" function (lib/parser_aux.c) within GnuTLS libtasn1 version 4.10 can be exploited to cause a stacked-based buffer overflow by tricking a user into processing a specially crafted assignments file via the e.g. asn1Coding utility.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade libtasn1 | Aug 30, 2017 | May 22, 2017 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | May 22, 2017 |
| Debian | — | Upgrade libtasn1-3Upgrade libtasn1-6 | May 23, 2017 | May 22, 2017 |
| Gentoo Linux | — | Upgrade dev-libs/libtasn1. | Oct 30, 2017 | May 22, 2017 |
| Huawei Euleros 2_0_sp2 | — | Upgrade libtasn1Upgrade libtasn1-devel | May 1, 2019 | May 22, 2017 |
| Huawei Euleros 2_0_sp3 | — | Upgrade libtasn1-develUpgrade libtasn1 | May 1, 2019 | May 22, 2017 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | May 18, 2017 |
| Suse | — | Upgrade libgnutls-develUpgrade libgnutls26-32bitUpgrade libtasn1-6Upgrade libtasn1Upgrade gnutlsUpgrade libtasn1-6-32bitUpgrade libgnutls26Upgrade libgnutls-extra26Upgrade libgnutls26-x86Upgrade libgnutls-extra-develUpgrade libtasn1-devel | Jul 17, 2017 | May 22, 2017 |
| Ubuntu | — | Upgrade libtasn1-3Upgrade libtasn1-6 | Jun 5, 2017 | May 22, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub