CVE-2014-3469

Publication date 5 June 2014

Last updated 24 July 2024


Ubuntu priority

The (1) asn1_read_value_type and (2) asn1_read_value functions in GNU Libtasn1 before 3.6 allows context-dependent attackers to cause a denial of service (NULL pointer dereference and crash) via a NULL value in an ivalue argument.

Status

Package Ubuntu Release Status
libtasn1-3 14.04 LTS trusty Not in release
13.10 saucy Ignored end of life
12.04 LTS precise
Fixed 2.10-1ubuntu1.2
10.04 LTS lucid
Fixed 2.4-1ubuntu0.2
libtasn1-6 14.04 LTS trusty
Fixed 3.4-3ubuntu0.1
13.10 saucy Ignored end of life
12.04 LTS precise Not in release
10.04 LTS lucid Not in release

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
libtasn1-6

References

Related Ubuntu Security Notices (USN)

    • USN-2294-1
    • Libtasn1 vulnerabilities
    • 22 July 2014

Other references