CVE-2014-3468
EPSS 9.8%
Description
The asn1_get_bit_der function in GNU Libtasn1 before 3.6 does not properly report an error when a negative bit length is identified, which allows context-dependent attackers to cause out-of-bounds access via crafted ASN.1 data.
How to fix CVE-2014-3468
To remediate CVE-2014-3468, upgrade the affected package to a fixed version below.
- Debian/libtasn1-6—upgrade to 3.6-1 or later
Is CVE-2014-3468 being exploited?
Moderate — EPSS is 9.8%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (1)
- from 0, < 3.6-1