VDB
DEBIAN-CVE-2014-3468
DEBIAN-CVE-2014-3468
PUBLISHED
The asn1_get_bit_der function in GNU Libtasn1 before 3.6 does not properly report an error when a negative bit length is identified, which allows context-dependent attackers to cause out-of-bounds access via crafted ASN.1 data.
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Debian:12 | libtasn1-6 | 0, 0, 0 |
| Debian:13 | libtasn1-6 | 0, 0, 0 |
| Debian:14 | libtasn1-6 | 0, 0, 0 |
| Debian:11 | libtasn1-6 | 0, 0, 0 |
Timeline
- Jun 5, 2014 CVE Published
- Apr 28, 2026 CVE Updated