Description
The _asn1_extract_der_octet function in lib/decoding.c in GNU Libtasn1 before 4.8, when used without the ASN1_DECODE_FLAG_STRICT_DER flag, allows remote attackers to cause a denial of service (infinite recursion) via a crafted certificate.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-495-1 | libtasn1-3 security update |
Debian DSA |
DSA-3568-1 | libtasn1-6 security update |
EUVD |
EUVD-2016-5015 | The _asn1_extract_der_octet function in lib/decoding.c in GNU Libtasn1 before 4.8, when used without the ASN1_DECODE_FLAG_STRICT_DER flag, allows remote attackers to cause a denial of service (infinite recursion) via a crafted certificate. |
Ubuntu USN |
USN-2957-1 | Libtasn1 vulnerability |
Ubuntu USN |
USN-2957-2 | Libtasn1 vulnerability |
References
History
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-06T00:17:30.800Z
Reserved: 2016-04-13T00:00:00.000Z
Link: CVE-2016-4008
No data.
Status : Modified
Published: 2016-05-05T18:59:10.380
Modified: 2026-05-06T22:30:45.220
Link: CVE-2016-4008
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
EUVD
Ubuntu USN