Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The asn1_get_bit_der function in GNU Libtasn1 before 3.6 does not properly report an error when a negative bit length is identified, which allows context-dependent attackers to cause out-of-bounds access via crafted ASN.1 data.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
GNU Libtasn1 数字错误漏洞
Vulnerability Description
GnuTLS是比利时Nikos Mavrogiannopoulos和瑞典Simon Josefsson软件开发者共同研发的一个免费的用于实现SSL、TLS和DTLS协议的安全通信库。GnuTLS libtasn1是软件开发者Fabio Fiorina所研发的一个用于GnuTLS中的ASN.1结构管理库。 GNU Libtasn1 3.5及之前版本中的‘asn1_get_bit_der’函数存在安全漏洞,该漏洞源于当程序确认负位长度时,没有报错。攻击者可借助特制的ASN.1数据利用该漏洞造成越边界访问。
CVSS Information
N/A
Vulnerability Type
N/A