CVE-2014-3469

The (1) asn1_read_value_type and (2) asn1_read_value functions in GNU Libtasn1 before 3.6 allows context-dependent attackers to cause a denial of service (NULL pointer dereference and crash) via a NULL value in an ivalue argument.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:N/I:N/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 92%
Affected Products (NVD)
VendorProductVersion
gnugnutls
𝑥
< 3.5.7
gnulibtasn1
𝑥
< 3.6
redhatvirtualization
6.0
debiandebian_linux
7.0
redhatenterprise_linux_desktop
5.0
redhatenterprise_linux_desktop
6.0
redhatenterprise_linux_desktop
7.0
redhatenterprise_linux_eus
6.5
redhatenterprise_linux_eus
7.3
redhatenterprise_linux_eus
7.4
redhatenterprise_linux_eus
7.5
redhatenterprise_linux_eus
7.6
redhatenterprise_linux_eus
7.7
redhatenterprise_linux_server
5.0
redhatenterprise_linux_server
6.0
redhatenterprise_linux_server
7.0
redhatenterprise_linux_server_aus
6.5
redhatenterprise_linux_server_aus
7.3
redhatenterprise_linux_server_aus
7.4
redhatenterprise_linux_server_aus
7.6
redhatenterprise_linux_server_aus
7.7
redhatenterprise_linux_server_tus
6.5
redhatenterprise_linux_server_tus
7.3
redhatenterprise_linux_server_tus
7.6
redhatenterprise_linux_server_tus
7.7
redhatenterprise_linux_workstation
5.0
redhatenterprise_linux_workstation
6.0
redhatenterprise_linux_workstation
7.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
libtasn1-6
bookworm
4.19.0-2
fixed
bullseye
4.16.0-2+deb11u1
fixed
sid
4.19.0-3
fixed
trixie
4.19.0-3
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libtasn1-3
lucid
Fixed 2.4-1ubuntu0.2
released
precise
Fixed 2.10-1ubuntu1.2
released
saucy
ignored
trusty
dne
libtasn1-6
lucid
dne
precise
dne
saucy
ignored
trusty
Fixed 3.4-3ubuntu0.1
released
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
libtasn1
suse enterprise desktop 15
4.13-2.15
fixed
suse enterprise sap 12 SP5
4.9-3.10.1
fixed
suse enterprise sap 15
4.13-2.15
fixed
suse enterprise server 12 SP5
4.9-3.10.1
fixed
suse enterprise server 15
4.13-2.15
fixed
libtasn1-6
suse enterprise desktop 15
4.13-2.15
fixed
suse enterprise sap 12 SP5
4.9-3.10.1
fixed
suse enterprise sap 15
4.13-2.15
fixed
suse enterprise server 12 SP5
4.9-3.10.1
fixed
suse enterprise server 15
4.13-2.15
fixed
libtasn1-6-32bit
suse enterprise sap 12 SP5
4.9-3.10.1
fixed
suse enterprise server 12 SP5
4.9-3.10.1
fixed
libtasn1-devel
suse enterprise desktop 15
4.13-2.15
fixed
suse enterprise sap 15
4.13-2.15
fixed
suse enterprise server 15
4.13-2.15
fixed
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
libtasn1
RHEL 6
0:2.3-6.el6_5
fixed
RHEL 7
0:3.3-5.el7_0
fixed
libtasn1-devel
RHEL 6
0:2.3-6.el6_5
fixed
RHEL 7
0:3.3-5.el7_0
fixed
libtasn1-tools
RHEL 6
0:2.3-6.el6_5
fixed
RHEL 7
0:3.3-5.el7_0
fixed
References