The _asn1_extract_der_octet function in lib/decoding.c in GNU Libtasn1 before 4.8, when used without the ASN1_DECODE_FLAG_STRICT_DER flag, allows remote attackers to cause a denial of service (infinite recursion) via a crafted certificate.
CVSS Details
- CVSS 3.1 Base Score: 5.9
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade libtasn1 | Aug 30, 2017 | May 5, 2016 |
| Debian | — | Upgrade libtasn1-6Upgrade libtasn1-3 | May 5, 2016 | May 5, 2016 |
| Freebsd | — | Upgrade libtasn1 | Dec 10, 2025 | Apr 21, 2016 |
| Gentoo Linux | — | Upgrade dev-libs/libtasn1. | Oct 30, 2017 | May 5, 2016 |
| Oracle Solaris | — | Upgrade entire/ to version 11.4-11.4.0.0.1.15.0 on Solaris 11.4 | Oct 19, 2018 | May 5, 2016 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Apr 11, 2016 |
| Suse | — | Upgrade libtasn1-3-32bitUpgrade libtasn1-3Upgrade libtasn1-6-32bitUpgrade libtasn1Upgrade libtasn1-3-x86Upgrade sles12-docker-imageUpgrade libtasn1-6Upgrade sles12sp1-docker-imageUpgrade libtasn1-devel | Jun 14, 2016 | May 5, 2016 |
| Ubuntu | — | Upgrade libtasn1-6Upgrade libtasn1-3 | May 2, 2016 | May 2, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub