CVE-2015-2806
Publication date 1 April 2015
Last updated 24 July 2024
Ubuntu priority
Stack-based buffer overflow in asn1_der_decoding in libtasn1 before 4.4 allows remote attackers to have unspecified impact via unknown vectors.
Status
Package | Ubuntu Release | Status |
---|---|---|
libtasn1-3 | ||
14.04 LTS trusty | Not in release | |
libtasn1-6 | ||
14.04 LTS trusty |
Fixed 3.4-3ubuntu0.2
|
|
Notes
tyhicks
In Precise and older, it may make sense to just do the one-line change of increasing the temp array to 22 bytes. More investigation needed.
Patch details
References
Related Ubuntu Security Notices (USN)
- USN-2559-1
- Libtasn1 vulnerability
- 8 April 2015