It was discovered that Libtasn1 incorrectly handled certain ASN.1 data structures. An attacker could exploit this with specially crafted ASN.1 data and cause applications using Libtasn1 to crash, resulting in a denial of service. (CVE-2014-3467)
It was discovered that Libtasn1 incorrectly handled negative bit lengths. An attacker could exploit this with specially crafted ASN.1 data and cause applications using Libtasn1 to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2014-3468)
It was discovered that Libtasn1 incorrectly handled certain ASN.1 data. An attacker could exploit this with specially crafted ASN.1 data and cause applications using Libtasn1 to crash, resulting in a denial of service. (CVE-2014-3469)
{
"availability": "No subscription required",
"binaries": [
{
"binary_name": "libtasn1-3-bin",
"binary_version": "3.4-3ubuntu0.1"
},
{
"binary_name": "libtasn1-3-dev",
"binary_version": "3.4-3ubuntu0.1"
},
{
"binary_name": "libtasn1-6",
"binary_version": "3.4-3ubuntu0.1"
},
{
"binary_name": "libtasn1-6-dev",
"binary_version": "3.4-3ubuntu0.1"
},
{
"binary_name": "libtasn1-bin",
"binary_version": "3.4-3ubuntu0.1"
}
]
}
{
"cves": [
{
"severity": [
{
"type": "Ubuntu",
"score": "medium"
}
],
"id": "CVE-2014-3467"
},
{
"severity": [
{
"type": "Ubuntu",
"score": "medium"
}
],
"id": "CVE-2014-3468"
},
{
"severity": [
{
"type": "Ubuntu",
"score": "medium"
}
],
"id": "CVE-2014-3469"
}
],
"ecosystem": "Ubuntu:14.04:LTS"
}