It was discovered that Libtasn1 incorrectly handled certain ASN.1 data structures. An attacker could exploit this with specially crafted ASN.1 data and cause applications using Libtasn1 to crash, resulting in a denial of service. (CVE-2014-3467)
It was discovered that Libtasn1 incorrectly handled negative bit lengths. An attacker could exploit this with specially crafted ASN.1 data and cause applications using Libtasn1 to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2014-3468)
It was discovered that Libtasn1 incorrectly handled certain ASN.1 data. An attacker could exploit this with specially crafted ASN.1 data and cause applications using Libtasn1 to crash, resulting in a denial of service. (CVE-2014-3469)
{
"binaries": [
{
"binary_version": "3.4-3ubuntu0.1",
"binary_name": "libtasn1-3-bin"
},
{
"binary_version": "3.4-3ubuntu0.1",
"binary_name": "libtasn1-3-dev"
},
{
"binary_version": "3.4-3ubuntu0.1",
"binary_name": "libtasn1-6"
},
{
"binary_version": "3.4-3ubuntu0.1",
"binary_name": "libtasn1-6-dev"
},
{
"binary_version": "3.4-3ubuntu0.1",
"binary_name": "libtasn1-bin"
}
],
"availability": "No subscription required"
}
{
"ecosystem": "Ubuntu:14.04:LTS",
"cves": [
{
"id": "CVE-2014-3467",
"severity": [
{
"type": "Ubuntu",
"score": "medium"
}
]
},
{
"id": "CVE-2014-3468",
"severity": [
{
"type": "Ubuntu",
"score": "medium"
}
]
},
{
"id": "CVE-2014-3469",
"severity": [
{
"type": "Ubuntu",
"score": "medium"
}
]
}
]
}