Bug 880738 (CVE-2014-3469) - VUL-0: CVE-2014-3469: libtasn1: Possible DoS by Null Dereference
Summary: VUL-0: CVE-2014-3469: libtasn1: Possible DoS by Null Dereference
Status: RESOLVED FIXED
Alias: CVE-2014-3469
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Deadline: 2014-06-09
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/99193/
Whiteboard: maint:running:57609:important maint:r...
Keywords:
Depends on:
Blocks:
 
Reported: 2014-05-30 12:28 UTC by Johannes Segitz
Modified: 2014-07-30 11:56 UTC (History)
5 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Johannes Segitz 2014-05-30 12:28:56 UTC
A NULL pointer dereference flaw was found in libtasn1's asn1_read_value_type() / asn1_read_value() function. If an application called the function with a NULL value for an ivalue argument to determine the amount of memory needed to store data to be read from the ASN.1 input, libtasn1 could incorrectly attempt to dereference the NULL pointer, causing an application using the library to crash.

Fixed upstream in libtasn1 3.6:
http://lists.gnu.org/archive/html/help-libtasn1/2014-05/msg00006.html

Please submit for SLE11-SP3, SLE12, openSUSE 12.3 and openSUSE 13.1.

References:
https://bugzilla.redhat.com/show_bug.cgi?id=1102329
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-3469
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3469
Comment 1 Swamp Workflow Management 2014-05-30 12:35:55 UTC
An update workflow for this issue was started.
This issue was rated as important.
Please submit fixed packages until 2014-06-06.
When done, reassign the bug to security-team@suse.de.
https://swamp.suse.de/webswamp/wf/57609
Comment 2 Marcus Schaefer 2014-05-30 12:40:06 UTC
again, not my playground

from the changelog the last significant version update was done by meissner@suse.com
other than that it looks like this package has no dedicated maintainer.

@Marcus Meissner, hope you don't mind
Comment 3 Swamp Workflow Management 2014-05-30 22:00:39 UTC
bugbot adjusting priority
Comment 4 Swamp Workflow Management 2014-06-02 10:15:51 UTC
An update workflow for this issue was started.
This issue was rated as important.
Please submit fixed packages until 2014-06-09.
When done, reassign the bug to security-team@suse.de.
https://swamp.suse.de/webswamp/wf/57618
Comment 5 Bernhard Wiedemann 2014-06-03 10:00:38 UTC
This is an autogenerated message for OBS integration:
This bug (880738) was mentioned in
https://build.opensuse.org/request/show/236130 Factory / libtasn1
Comment 9 Scott Reeves 2014-06-16 22:11:59 UTC
Fixes submitted for SLE 11, SLE 12, openSUSE 12.3 and openSUSE 13.1.

I would suggest waiting for the related submission for bnc#880737 before pushing.
Comment 10 Bernhard Wiedemann 2014-06-16 23:00:22 UTC
This is an autogenerated message for OBS integration:
This bug (880738) was mentioned in
https://build.opensuse.org/request/show/237601 13.1 / libtasn1
https://build.opensuse.org/request/show/237602 12.3 / libtasn1
Comment 11 Federico Mena Quintero 2014-07-14 21:19:08 UTC
Resubmitted, with resolved conflicts for osc, with request 41158.
Comment 12 Federico Mena Quintero 2014-07-15 00:29:57 UTC
Please ignore the previous comment; I posted it to the wrong bug.
Comment 13 Swamp Workflow Management 2014-07-24 01:05:55 UTC
SUSE-SU-2014:0931-1: An update that fixes three vulnerabilities is now available.

Category: security (important)
Bug References: 880735,880737,880738
CVE References: CVE-2014-3467,CVE-2014-3468,CVE-2014-3469
Sources used:
SUSE Linux Enterprise Software Development Kit 11 SP3 (src):    libtasn1-1.5-1.28.1
SUSE Linux Enterprise Server 11 SP3 for VMware (src):    libtasn1-1.5-1.28.1
SUSE Linux Enterprise Server 11 SP3 (src):    libtasn1-1.5-1.28.1
SUSE Linux Enterprise Desktop 11 SP3 (src):    libtasn1-1.5-1.28.1
Comment 14 Bernhard Wiedemann 2014-07-26 09:00:33 UTC
This is an autogenerated message for OBS integration:
This bug (880738) was mentioned in
https://build.opensuse.org/request/show/242449 Factory / libtasn1
Comment 16 Marcus Meissner 2014-07-30 11:56:30 UTC
released