Lucene search

K
cve[email protected]CVE-2014-3468
HistoryJun 05, 2014 - 8:55 p.m.

CVE-2014-3468

2014-06-0520:55:06
CWE-131
web.nvd.nist.gov
58
cve-2014-3468
gnu libtasn1
security vulnerability
asn.1
out-of-bounds access

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

5.8 Medium

AI Score

Confidence

High

0.007 Low

EPSS

Percentile

80.9%

The asn1_get_bit_der function in GNU Libtasn1 before 3.6 does not properly report an error when a negative bit length is identified, which allows context-dependent attackers to cause out-of-bounds access via crafted ASN.1 data.

Affected configurations

NVD
Node
gnugnutlsRange<3.5.7
OR
gnulibtasn1Range<3.6
Node
redhatvirtualizationMatch6.0
OR
debiandebian_linuxMatch7.0
OR
redhatenterprise_linux_desktopMatch5.0
OR
redhatenterprise_linux_desktopMatch6.0
OR
redhatenterprise_linux_desktopMatch7.0
OR
redhatenterprise_linux_eusMatch6.5
OR
redhatenterprise_linux_eusMatch7.3
OR
redhatenterprise_linux_eusMatch7.4
OR
redhatenterprise_linux_eusMatch7.5
OR
redhatenterprise_linux_eusMatch7.6
OR
redhatenterprise_linux_eusMatch7.7
OR
redhatenterprise_linux_serverMatch5.0
OR
redhatenterprise_linux_serverMatch6.0
OR
redhatenterprise_linux_serverMatch7.0
OR
redhatenterprise_linux_server_ausMatch6.5
OR
redhatenterprise_linux_server_ausMatch7.3
OR
redhatenterprise_linux_server_ausMatch7.4
OR
redhatenterprise_linux_server_ausMatch7.6
OR
redhatenterprise_linux_server_ausMatch7.7
OR
redhatenterprise_linux_server_tusMatch6.5
OR
redhatenterprise_linux_server_tusMatch7.3
OR
redhatenterprise_linux_server_tusMatch7.6
OR
redhatenterprise_linux_server_tusMatch7.7
OR
redhatenterprise_linux_workstationMatch5.0
OR
redhatenterprise_linux_workstationMatch6.0
OR
redhatenterprise_linux_workstationMatch7.0
Node
suselinux_enterprise_desktopMatch11sp3
OR
suselinux_enterprise_high_availability_extensionMatch11sp3
OR
suselinux_enterprise_serverMatch11sp1ltss
OR
suselinux_enterprise_serverMatch11sp2ltss
OR
suselinux_enterprise_serverMatch11sp3-
OR
suselinux_enterprise_serverMatch11sp3vmware
OR
suselinux_enterprise_software_development_kitMatch11sp3
Node
debiandebian_linuxMatch7.0
Node
f5arx_firmwareRange6.0.06.4.0
AND
f5arxMatch-

References

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

5.8 Medium

AI Score

Confidence

High

0.007 Low

EPSS

Percentile

80.9%