Debian Security Advisory
DSA-3861-1 libtasn1-6 -- security update
- Date Reported:
- 24 May 2017
- Affected Packages:
- libtasn1-6
- Vulnerable:
- Yes
- Security database references:
- In the Debian bugtracking system: Bug 863186.
In Mitre's CVE dictionary: CVE-2017-6891. - More information:
-
Jakub Jirasek of Secunia Research discovered that libtasn1, a library used to handle Abstract Syntax Notation One structures, did not properly validate its input. This would allow an attacker to cause a crash by denial-of-service, or potentially execute arbitrary code, by tricking a user into processing a maliciously crafted assignments file.
For the stable distribution (jessie), this problem has been fixed in version 4.2-3+deb8u3.
We recommend that you upgrade your libtasn1-6 packages.