CVE-2016-4008 PUBLISHED

The _asn1_extract_der_octet function in lib/decoding.c in GNU Libtasn1 before 4.8, when used without the ASN1_DECODE_FLAG_STRICT_DER flag, allows remote attackers to cause a denial of service (infinite recursion) via a crafted certificate.

EPSS 5.05% · 89.7th percentile

Risk Scores

EPSS Score
5.05%
89.7th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSlibtasn1-60, 4.5-2, 4.7-2
Ubuntu:14.04:LTSlibtasn1-63.4-3ubuntu0.1, 0, 3.4-3ubuntu0.3

Timeline

References

Open in Interactive Console →