Alerts This Week
Warning Icon 1 535
Alerts This Week
Warning Icon 1 535

Fedora 20 Security Update: Critical Libtasn1 Stack Overflow Fix

fedora
Calendar Grey April 18, 2015
Dist Fedora Esm H88
Important security patch for Fedora 20's libtasn1 released to address stack overflow vulnerability in DER decoder. Update immediately!
backported fix for stack overflow in DER decoder

Summary

A library that provides Abstract Syntax Notation One (ASN.1, as specified

by the X.680 ITU-T recommendation) parsing and structures management, and

Distinguished Encoding Rules (DER, as per X.690) encoding and decoding functions.

Update Information:

backported fix for stack overflow in DER decoder

Change Log

* Mon Mar 30 2015 Nikos Mavrogiannopoulos - 3.8-3 - backported fix for stack overflow in DER decoder * Thu Sep 4 2014 Nikos Mavrogiannopoulos - 3.8-2 - added bug fix for octet string decoding (#1138218) * Mon Aug 25 2014 Nikos Mavrogiannopoulos - 3.8-1 - new upstream release * Mon Jun 30 2014 Nikos Mavrogiannopoulos - 3.7-1 - new upstream release * Mon May 26 2014 Nikos Mavrogiannopoulos - 3.6-1 - new upstream release * Fri May 2 2014 Nikos Mavrogiannopoulos - 3.5-1 - new upstream release * Wed Nov 27 2013 Nikos Mavrogiannopoulos - 3.4-1 - new upstream release

References


[ 1 ] Bug #1207192 - CVE-2015-2806 libtasn1: stack overflow in asn1_der_decoding https://bugzilla.redhat.com/show_bug.cgi?id=1207192

Update Instructions

This update can be installed with the "yum" update program. Use su -c 'yum update libtasn1' at the command line. For more information, refer to "Managing Software with yum", available at .

Severity
critical
Lowest
Low
Medium
High
Critical

Name: libtasn1
Product: Fedora 20
Version: 3.8
Release: 3.fc20
URL:
Summary: The ASN.1 library used in GNUTLS

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here