VDB

DEBIAN-CVE-2014-3468

DEBIAN-CVE-2014-3468 PUBLISHED

The asn1_get_bit_der function in GNU Libtasn1 before 3.6 does not properly report an error when a negative bit length is identified, which allows context-dependent attackers to cause out-of-bounds access via crafted ASN.1 data.

Affected Products

VendorProductVersions
Debian:12libtasn1-60, 0, 0
Debian:13libtasn1-60, 0, 0
Debian:14libtasn1-60, 0, 0
Debian:11libtasn1-60, 0, 0

Timeline

  • Jun 5, 2014 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›