Tiny ASN.1 Library (libtasn1) before 0.2.18, as used by (1) GnuTLS 1.2.x before 1.2.10 and 1.3.x before 1.3.4, and (2) GNU Shishi, allows attackers to crash the DER decoder and possibly execute arbitrary code via "out-of-bounds access" caused by invalid input, as demonstrated by the ProtoVer SSL test suite.
                
            References
                    Configurations
                    Configuration 1 (hide)
            
            
  | 
    
History
                    21 Nov 2024, 00:06
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () http://josefsson.org/cgi-bin/viewcvs.cgi/gnutls/tests/certder.c?view=markup - | |
| References | () http://josefsson.org/cgi-bin/viewcvs.cgi/libtasn1/NEWS?root=gnupg-mirror&view=markup - | |
| References | () http://josefsson.org/gnutls/releases/libtasn1/libtasn1-0.2.18-from-0.2.17.patch - | |
| References | () http://lists.gnupg.org/pipermail/gnutls-dev/2006-February/001058.html - | |
| References | () http://lists.gnupg.org/pipermail/gnutls-dev/2006-February/001059.html - | |
| References | () http://lists.gnupg.org/pipermail/gnutls-dev/2006-February/001060.html - | |
| References | () http://rhn.redhat.com/errata/RHSA-2006-0207.html - | |
| References | () http://secunia.com/advisories/18794 - | |
| References | () http://secunia.com/advisories/18815 - | |
| References | () http://secunia.com/advisories/18830 - | |
| References | () http://secunia.com/advisories/18832 - | |
| References | () http://secunia.com/advisories/18898 - | |
| References | () http://secunia.com/advisories/18918 - | |
| References | () http://secunia.com/advisories/19080 - | |
| References | () http://secunia.com/advisories/19092 - | |
| References | () http://securityreason.com/securityalert/446 - | |
| References | () http://securitytracker.com/id?1015612 - | |
| References | () http://www.debian.org/security/2006/dsa-985 - | |
| References | () http://www.debian.org/security/2006/dsa-986 - | |
| References | () http://www.gentoo.org/security/en/glsa/glsa-200602-08.xml - | |
| References | () http://www.gleg.net/protover_ssl.shtml - | |
| References | () http://www.mandriva.com/security/advisories?name=MDKSA-2006:039 - | |
| References | () http://www.osvdb.org/23054 - | |
| References | () http://www.redhat.com/archives/fedora-announce-list/2006-February/msg00043.html - | |
| References | () http://www.securityfocus.com/archive/1/424538/100/0/threaded - | |
| References | () http://www.securityfocus.com/bid/16568 - | |
| References | () http://www.trustix.org/errata/2006/0008 - | |
| References | () http://www.vupen.com/english/advisories/2006/0496 - | |
| References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/24606 - | |
| References | () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10540 - | |
| References | () https://usn.ubuntu.com/251-1/ - | 
Information
                Published : 2006-02-10 18:06
Updated : 2025-04-03 01:03
NVD link : CVE-2006-0645
Mitre link : CVE-2006-0645
CVE.ORG link : CVE-2006-0645
JSON object : View
Products Affected
                free_software_foundation_inc.
- libtasn1
 
CWE
                