Back to Database
Status published
Medium
CVE-2014-3467
Multiple unspecified vulnerabilities in the DER decoder in GNU Libtasn1...
Vulnerability Description
Multiple unspecified vulnerabilities in the DER decoder in GNU Libtasn1 before 3.6, as used in GnuTLS, allow remote attackers to cause a denial of service (out-of-bounds read) via crafted ASN.1 data.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2014-3467
Credits & Attribution
No credits recorded in the NVD database.
References
- http://secunia.com/advisories/60320
- http://www.debian.org/security/2014/dsa-3056
- http://www.novell.com/support/kb/doc.php?id=7015302
- http://secunia.com/advisories/59057
- http://lists.opensuse.org/opensuse-security-announce/2014-06/msg00002.html
- http://support.f5.com/kb/en-us/solutions/public/15000/400/sol15423.html
- http://linux.oracle.com/errata/ELSA-2014-0596.html
- http://www.mandriva.com/security/advisories?name=MDVSA-2015:116
- http://secunia.com/advisories/59021
- http://secunia.com/advisories/61888
- http://advisories.mageia.org/MGASA-2014-0247.html
- http://rhn.redhat.com/errata/RHSA-2014-0815.html
- http://rhn.redhat.com/errata/RHSA-2014-0596.html
- http://lists.gnu.org/archive/html/help-libtasn1/2014-05/msg00006.html
- http://www.novell.com/support/kb/doc.php?id=7015303
- http://linux.oracle.com/errata/ELSA-2014-0594.html
- http://secunia.com/advisories/58591
- http://rhn.redhat.com/errata/RHSA-2014-0687.html
- http://secunia.com/advisories/58614
- https://bugzilla.redhat.com/show_bug.cgi?id=1102022
- http://lists.opensuse.org/opensuse-security-announce/2014-06/msg00015.html
- http://rhn.redhat.com/errata/RHSA-2014-0594.html
- http://secunia.com/advisories/60415
- http://secunia.com/advisories/59408
More from gnu
View All →CVE-2024-10524
GNU Wget is vulnerable to an SSRF attack when accessing partially-user-controlled shorthand URLs
Medium
6.5
CVE-2022-48339
An issue was discovered in GNU Emacs through 28.2. htmlfontify.el...
Unknown
0
CVE-2022-48338
An issue was discovered in GNU Emacs through 28.2. In...
Unknown
0
CVE-2022-48337
GNU Emacs through 28.2 allows attackers to execute commands via...
Unknown
0
CVE-2022-48303
GNU Tar through 1.34 has a one-byte out-of-bounds read that...
Unknown
0
Affected Vendor
Affected Software
gnutls, libtasn1, virtualization, debian linux, enterprise linux desktop, enterprise linux eus, enterprise linux server, enterprise linux server aus, enterprise linux server tus, enterprise linux workstation, linux enterprise desktop, linux enterprise high availability extension, linux enterprise server, linux enterprise software development kit, arx firmware
Vulnerable Versions:
0, 6.0, 7.0, 5.0, 6.5, 7.3, 7.4, 7.5, 7.6, 7.7, 11, 6.0.0
Timeline
Official Publish:
June 5th, 2014
Last Modified:
August 6th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.