CVE-2017-6891
Summary
| CVE | CVE-2017-6891 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-05-22 19:29:00 UTC |
| Updated | 2023-11-07 02:49:00 UTC |
| Description | Two errors in the "asn1_find_node()" function (lib/parser_aux.c) within GnuTLS libtasn1 version 4.10 can be exploited to cause a stacked-based buffer overflow by tricking a user into processing a specially crafted assignments file via the e.g. asn1Coding utility. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Computer Security Research - Secunia |
MISC |
secuniaresearch.flexerasoftware.com |
Patch, Third Party Advisory |
| Savannah Git Hosting - libtasn1.git/commit |
CONFIRM |
git.savannah.gnu.org |
Patch, Vendor Advisory |
| [bookkeeper-issues] 20210628 [GitHub] [bookkeeper] padma81 opened a new issue #2746: Security Vulnerabilities in CentOS 7 image, Upgrade image to CentOS 8 |
|
lists.apache.org |
|
| GNU Libtasn1: Multiple vulnerabilities (GLSA 201710-11) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| Pony Mail! |
MLIST |
lists.apache.org |
|
| [security-announce] openSUSE-SU-2019:1510-1: moderate: Security update f |
SUSE |
lists.opensuse.org |
|
| Security Advisory SA76125 - GnuTLS libtasn1 "asn1_find_node()" Buffer Overflow Vulnerabilities - Secunia |
MISC |
secuniaresearch.flexerasoftware.com |
Permissions Required |
| Pony Mail! |
MLIST |
lists.apache.org |
|
| [bookkeeper-issues] 20210629 [GitHub] [bookkeeper] padma81 opened a new issue #2746: Security Vulnerabilities in CentOS 7 image, Upgrade image to CentOS 8 |
|
lists.apache.org |
|
| Savannah Git Hosting - libtasn1.git/commit |
|
git.savannah.gnu.org |
|
| libtASN1 Stack Overflow in asn1_find_node() in Processing Assignment Files Lets Remote Users Execute Arbitrary Code - SecurityTracker |
SECTRACK |
www.securitytracker.com |
|
| GnuTLS CVE-2017-6891 Stack Buffer Overflow Vulnerability |
BID |
www.securityfocus.com |
|
| Debian -- Security Information -- DSA-3861-1 libtasn1-6 |
DEBIAN |
www.debian.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 710419 Gentoo Linux GNU Libtasn1 Multiple Vulnerabilities (GLSA 201710-11)