Vulnerability Database

289,599

Total vulnerabilities in the database

CVE-2014-3468

The asn1_get_bit_der function in GNU Libtasn1 before 3.6 does not properly report an error when a negative bit length is identified, which allows context-dependent attackers to cause out-of-bounds access via crafted ASN.1 data.

  • Published: Jun 5, 2014
  • Updated: Apr 13, 2023
  • CVE: CVE-2014-3468
  • Severity: High
  • Exploit:

CVSS v2:

  • Severity: High
  • Score: 7.5
  • AV:N/AC:L/Au:N/C:P/I:P/A:P

CWEs:

Software From Fixed in
gnu / gnutls - 3.5.7
gnu / libtasn1 - 3.6
redhat / enterprise_linux_desktop 7.0 7.0.x
redhat / enterprise_linux_server 5.0 5.0.x
redhat / enterprise_linux_workstation 7.0 7.0.x
redhat / enterprise_linux_server 7.0 7.0.x
redhat / enterprise_linux_workstation 5.0 5.0.x
debian / debian_linux 7.0 7.0.x
redhat / enterprise_linux_server_aus 6.5 6.5.x
redhat / enterprise_linux_server_tus 6.5 6.5.x
redhat / enterprise_linux_desktop 6.0 6.0.x
redhat / enterprise_linux_server 6.0 6.0.x
redhat / enterprise_linux_workstation 6.0 6.0.x
redhat / enterprise_linux_server_tus 7.3 7.3.x
redhat / enterprise_linux_desktop 5.0 5.0.x
redhat / enterprise_linux_server_aus 7.3 7.3.x
redhat / enterprise_linux_server_aus 7.4 7.4.x
redhat / enterprise_linux_eus 7.3 7.3.x
redhat / enterprise_linux_eus 7.4 7.4.x
redhat / enterprise_linux_eus 7.5 7.5.x
redhat / enterprise_linux_server_tus 7.6 7.6.x
redhat / enterprise_linux_server_aus 7.6 7.6.x
redhat / enterprise_linux_eus 7.6 7.6.x
redhat / enterprise_linux_server_aus 7.7 7.7.x
redhat / enterprise_linux_server_tus 7.7 7.7.x
redhat / enterprise_linux_eus 7.7 7.7.x
redhat / enterprise_linux_eus 6.5 6.5.x
redhat / virtualization 6.0 6.0.x
suse / linux_enterprise_server 11-sp1 11-sp1.x
suse / linux_enterprise_desktop 11-sp3 11-sp3.x
suse / linux_enterprise_server 11-sp3 11-sp3.x
suse / linux_enterprise_software_development_kit 11-sp3 11-sp3.x
suse / linux_enterprise_server 11-sp2 11-sp2.x
suse / linux_enterprise_high_availability_extension 11-sp3 11-sp3.x
f5 / arx_firmware 6.0.0 6.4.0.x