Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Mageia 8: 2022-0414 Critical Update for LibTasn1 Off-By-One Flaw

mageia
Calendar Grey November 8, 2022
Dist Mageia Esm H88
New libtasn1 updates fix serious vulnerabilities impacting Mageia versions. For further details, visit our advisory section.
GNU Libtasn1 before 4.19.0 has an ETYPE_OK off-by-one array size check that affects asn1_encode_simple_der

Summary

GNU Libtasn1 before 4.19.0 has an ETYPE_OK off-by-one array size check that affects asn1_encode_simple_der. (CVE-2021-46848)

References

- https://bugs.mageia.org/show_bug.cgi?id=31039

- https://lists.suse.com/pipermail/sle-security-updates/2022-October/012715.html

-

- https://ubuntu.com/security/notices/USN-5707-1

- https://www.cve.org/CVERecord?id=CVE-2021-46848

Resolution

SRPMS

- 8/core/libtasn1-4.16.0-4.1.mga8

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 08 Nov 2022
URL: https://advisories.mageia.org/MGASA-2022-0414.html
Type: security
CVE: CVE-2021-46848

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here