Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 465
Alerts This Week
Warning Icon 1 465

Fedora 26: FEDORA-2017-d5cf1a55ce Critical: Risk of Buffer Overflow

fedora
Calendar Grey June 9, 2017
Scroller Fedora
Essential security patch for mingw-libtasn1 tackling encoding flaws and buffer overflow vulnerabilities in Fedora 26.
Noteworthy changes in release 4.11 (released 2017-05-27) [stable] - Introduced the ASN1_TIME_ENCODING_ERROR error code to indicate an invalid encoding in the DER time fields

Summary

libtasn1 is the ASN.1 library used in GNUTLS.

This package contains the MinGW Windows cross compiled libtasn1 library.

Noteworthy changes in release 4.11 (released 2017-05-27) [stable] - Introduced

the ASN1_TIME_ENCODING_ERROR error code to indicate an invalid encoding in the

DER time fields. - Introduced flag ASN1_DECODE_FLAG_ALLOW_INCORRECT_TIME. This

flag allows decoding errors in time fields even when in strict DER mode.

That is introduced in order to allow toleration of invalid times in X.509

certificates (which are common) even though strict DER adherence is enforced

in other fields. - Added safety check in asn1_find_node(). That prevents a crash

when a very long variable name is provided by the developer. Note that this to

be exploited requires controlling the ASN.1 definitions used by the developer,

i.e., the 'name' parameter of asn1_write_value() or asn1_read_value(). The

library is not designed to protect against malicious manipulation of the

developer assigned variable names. Reported by Jakub Jirasek. Noteworthy

changes in release 4.10 (released 2017-01-16) [stable] - Updated gnulib -Removed -Werror from default compiler flags - Fixed undefined behavior when

negating integers in _asn1_ltostr(). Issue found by oss-fuzz project (via

gnutls): https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=388 - Pass the

correct length to _asn1_get_indefinite_length_string in asn1_get_length_ber.

This addresses reading 1-byte past the end of data. Issue found by oss-fuzz

project (via gnutls): https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=330 https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=331

[ 1 ] Bug #1456764 - CVE-2017-6891 mingw-libtasn1: libtasn1: Stack-based buffer overflow in asn1_find_node() [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1456764

su -c 'dnf upgrade mingw-libtasn1' at the command line.

For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 26
Version: 4.12
Release: 1.fc26
URL:
Summary: MinGW Windows libtasn1 library

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.