Back to search
CVE-2017-6891
Published: May 22, 2017
Modified: Aug 5, 2024
PUBLISHED
Description
Two errors in the "asn1_find_node()" function (lib/parser_aux.c) within GnuTLS libtasn1 version 4.10 can be exploited to cause a stacked-based buffer overflow by tricking a user into processing a specially crafted assignments file via the e.g. asn1Coding utility.
| Vendor | Product | Versions |
|---|---|---|
Flexera Software LLC | GnuTLS libtasn1 | affected 4.10. Other versions may also be affected. |
References
GLSA-201710-11
vendor-advisory
x_refsource_GENTOO
DSA-3861
vendor-advisory
x_refsource_DEBIAN
https://secuniaresearch.flexerasoftware.com/advisories/76125/
x_refsource_MISC
98641
vdb-entry
x_refsource_BID
1038619
vdb-entry
x_refsource_SECTRACK
openSUSE-SU-2019:1510
vendor-advisory
x_refsource_SUSE
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now