The _asn1_extract_der_octet function in lib/decoding.c in GNU Libtasn1 before 4.8, when used without the ASN1_DECODE_FLAG_STRICT_DER flag, allows remote attackers to cause a denial of service (infinite recursion) via a crafted certificate.
CVSS Details
- CVSS 3.1 Base Score: 5.9
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | alpine-linux-upgrade-libtasn1 | Aug 30, 2017 | May 5, 2016 |
| Debian | debian-upgrade-libtasn1-3debian-upgrade-libtasn1-6 | May 5, 2016 | May 5, 2016 | |
| Freebsd | freebsd-upgrade-package-libtasn1 | Dec 10, 2025 | Apr 21, 2016 | |
| Gentoo Linux | gentoo-linux-upgrade-dev-libs-libtasn1 | Oct 30, 2017 | May 5, 2016 | |
| Oracle Solaris | oracle-solaris-11-4-upgrade-entire-11-4-11-4-0-0-1-15-0 | Oct 19, 2018 | May 5, 2016 | |
| Redhat_linux | — | no-fix-redhat-rpm-package | Jul 9, 2025 | Apr 11, 2016 |
| Suse | — | suse-upgrade-libtasn1suse-upgrade-libtasn1-3suse-upgrade-libtasn1-3-32bitsuse-upgrade-libtasn1-3-x86suse-upgrade-libtasn1-6suse-upgrade-libtasn1-6-32bitsuse-upgrade-libtasn1-develsuse-upgrade-sles12-docker-imagesuse-upgrade-sles12sp1-docker-image | Jun 14, 2016 | May 5, 2016 |
| Ubuntu | ubuntu-upgrade-libtasn1-3ubuntu-upgrade-libtasn1-6 | May 2, 2016 | May 2, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub