CVE-2017-6891
Description
Two errors in the asn1_find_node() function (lib/parser_aux.c) within GnuTLS libtasn1 version 4.10 can be exploited to cause a stacked-based buffer overflow by tricking a user into processing a specially crafted assignments file via the e.g. asn1Coding utility.
Risk Information
Base Score
8.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
1.015
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| Library to manage ASN.1 structures (USN-3309-1) libtasn1-6_4.9-4ubuntu0.1_i386.deb | Linux |
| Library to manage ASN.1 structures (USN-3309-1) libtasn1-6_4.9-4ubuntu0.1_amd64.deb | Linux |
| Library to manage ASN.1 structures (USN-3309-1) libtasn1-6_4.10-1ubuntu0.1_i386.deb | Linux |
| Library to manage ASN.1 structures (USN-3309-1) libtasn1-6_4.10-1ubuntu0.1_amd64.deb | Linux |
| libtasn1-6 security update(DSA-3861-1) libtasn1-6_4.2-3+deb8u3_kfreebsd-i386.deb | Linux |
| libtasn1-6 security update(DSA-3861-1) libtasn1-6_4.2-3+deb8u3_kfreebsd-amd64.deb | Linux |
| SUSE-SU-2017:1886-1(SUSE Linux Enterprise Server 11-SP4 ) gnutls-2.4.1-24.39.70.1.x86_64.rpm | Linux |
| SUSE-SU-2017:1886-1(SUSE Linux Enterprise Server 11-SP4 ) libgnutls-extra26-2.4.1-24.39.70.1.x86_64.rpm | Linux |
| SUSE-SU-2017:1886-1(SUSE Linux Enterprise Server 11-SP4 ) libgnutls26-2.4.1-24.39.70.1.x86_64.rpm | Linux |
| SUSE-SU-2017:1886-1(SUSE Linux Enterprise Server 11-SP4 ) libgnutls26-32bit-2.4.1-24.39.70.1.x86_64.rpm | Linux |
| SUSE-SU-2019:1379-1(SUSE Linux Enterprise Desktop 12-SP4 ) libtasn1-4.9-3.10.1.x86_64.rpm | Linux |
| SUSE-SU-2019:1379-1(SUSE Linux Enterprise Desktop 12-SP3 ) libtasn1-6-4.9-3.10.1.x86_64.rpm | Linux |
| SUSE-SU-2019:1379-1(SUSE Linux Enterprise Desktop 12-SP3 ) libtasn1-6-32bit-4.9-3.10.1.x86_64.rpm | Linux |
| SUSE-SU-2019:1379-1(SUSE Linux Enterprise Desktop 12-SP3 ) libtasn1-6-debuginfo-4.9-3.10.1.x86_64.rpm | Linux |
| SUSE-SU-2019:1379-1(SUSE Linux Enterprise Desktop 12-SP3 ) libtasn1-6-debuginfo-32bit-4.9-3.10.1.x86_64.rpm | Linux |
| SUSE-SU-2019:1379-1(SUSE Linux Enterprise Desktop 12-SP3 ) libtasn1-debuginfo-4.9-3.10.1.x86_64.rpm | Linux |
| SUSE-SU-2019:1379-1(SUSE Linux Enterprise Desktop 12-SP3 ) libtasn1-debugsource-4.9-3.10.1.x86_64.rpm | Linux |
Patch Details
No records foundReferences
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234