CVE-2006-0645
Summary
| CVE | CVE-2006-0645 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-02-10 18:06:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | Tiny ASN.1 Library (libtasn1) before 0.2.18, as used by (1) GnuTLS 1.2.x before 1.2.10 and 1.3.x before 1.3.4, and (2) GNU Shishi, allows attackers to crash the DER decoder and possibly execute arbitrary code via "out-of-bounds access" caused by invalid input, as demonstrated by the ProtoVer SSL test suite. |
Risk And Classification
Primary CVSS: v2.0 7.5 from [email protected]
AV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS: 0.037210000 probability, percentile 0.879980000 (date 2026-04-16)
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Advisories - Mandriva Linux | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| USN-251-1: libtasn vulnerability | Ubuntu security notices | af854a3a-2127-422b-91ae-364da2661108 | usn.ubuntu.com | |
| [gnutls-dev] GnuTLS 1.3.4 - Experimental - Security release | af854a3a-2127-422b-91ae-364da2661108 | lists.gnupg.org | |
| GLEG Ltd. - Information Security Company | af854a3a-2127-422b-91ae-364da2661108 | www.gleg.net | |
| Fedora update for gnutls - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| GNUTLS LibTASN1 DER Decoding Denial of Service Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| SecurityTracker.com Archives - GnuTLS libtasn1 DER Decoding Bugs Let Remote Users Deny Service | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| Red Hat update for gnutls - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| www.trustix.org/errata/2006/0008 | af854a3a-2127-422b-91ae-364da2661108 | www.trustix.org | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| 404 Not Found | af854a3a-2127-422b-91ae-364da2661108 | josefsson.org | |
| rhn.redhat.com | Red Hat Support | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| Ubuntu update for libtasn - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| GnuTLS libtasn1 DER Decoding Denial of Service Vulnerabilities - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| SecurityReason - libtasn vulnerability | af854a3a-2127-422b-91ae-364da2661108 | securityreason.com | |
| [gnutls-dev] GnuTLS 1.2.10 - Security release | af854a3a-2127-422b-91ae-364da2661108 | lists.gnupg.org | |
| Mandriva update for gnutls - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Repository - markup - gnupg-mirror: libtasn1/NEWS | af854a3a-2127-422b-91ae-364da2661108 | josefsson.org | |
| Gentoo Linux Documentation -- libtasn1, GNU TLS: Security flaw in DER decoding | af854a3a-2127-422b-91ae-364da2661108 | www.gentoo.org | |
| Gentoo update for libtasn1/gnutls - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Debian update for libtasn1-2 - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Debian update for gnutls11 - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| www.osvdb.org/23054 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| Debian -- Security Information -- DSA-985-1 libtasn1-2 | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| Debian -- Security Information -- DSA-986-1 gnutls11 | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| [SECURITY] Fedora Core 4 Update: gnutls-1.0.25-2.FC4 | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| 404 Not Found | af854a3a-2127-422b-91ae-364da2661108 | josefsson.org | |
| [gnutls-dev] Libtasn1 0.2.18 - Tiny ASN.1 Library - Security release | af854a3a-2127-422b-91ae-364da2661108 | lists.gnupg.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.