Jakub Jirasek of Secunia Research discovered that libtasn1 did not
properly validate its input. This would allow an attacker to cause a
crash by denial-of-service, or potentially execute arbitrary code, by
tricking a user into processing a maliciously crafted assignments file
(CVE-2017-6891).