← Terug naar CVE-database
Beschrijving
The asn1_get_bit_der function in GNU Libtasn1 before 3.6 does not properly report an error when a negative bit length is identified, which allows context-dependent attackers to cause out-of-bounds access via crafted ASN.1 data.
Vendors
Gnu
Redhat
Debian
Suse
F5
Affected products
Gnutls
Libtasn1
Virtualization
Debian Linux
Enterprise Linux Desktop
Enterprise Linux Eus
Enterprise Linux Server
Enterprise Linux Server Aus
Enterprise Linux Server Tus
Enterprise Linux Workstation
Linux Enterprise Desktop
Linux Enterprise High Availability Extension
Linux Enterprise Server
Linux Enterprise Software Development Kit
Arx Firmware
Arx