Bug 982779 (CVE-2016-4008) - VUL-0: CVE-2016-4008: libtasn1: infinite loop while parsing DER certificates
Summary: VUL-0: CVE-2016-4008: libtasn1: infinite loop while parsing DER certificates
Status: RESOLVED FIXED
Alias: CVE-2016-4008
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/167799/
Whiteboard: CVSSv2:SUSE:CVE-2016-4008:4.3:(AV:N/A...
Keywords:
Depends on:
Blocks:
 
Reported: 2016-06-02 13:56 UTC by Marcus Meissner
Modified: 2020-09-24 12:23 UTC (History)
4 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Comment 1 Bjørn Lie 2016-06-02 16:13:59 UTC
Hi Marcus

Why was this bug assigned to us GNOME folks?
Comment 2 Marcus Meissner 2016-06-02 16:19:36 UTC
in suse the package is maintained by the GNOME group. 

externally it is apparently me :/
Comment 3 Swamp Workflow Management 2016-06-02 22:00:22 UTC
bugbot adjusting priority
Comment 4 Marcus Meissner 2016-06-03 13:30:00 UTC
sles submitted today, opensuse next week
Comment 5 Bernhard Wiedemann 2016-06-03 14:01:09 UTC
This is an autogenerated message for OBS integration:
This bug (982779) was mentioned in
https://build.opensuse.org/request/show/399983 13.2 / libtasn1
Comment 7 Marcus Meissner 2016-06-06 08:48:24 UTC
openszuse 13.2 submitted, 42.1 will come from sles 12.

factory is already updated, added references.

gnutls: needs checking
Comment 8 Marcus Meissner 2016-06-07 09:21:09 UTC
sle12 gnutls - uses external libtasn1.

sle11 gnutls - uses internal libtasn1 ...  might be affected, but the code looks quite different :/
Comment 9 Swamp Workflow Management 2016-06-14 09:10:02 UTC
openSUSE-SU-2016:1567-1: An update that solves two vulnerabilities and has one errata is now available.

Category: security (moderate)
Bug References: 929414,961491,982779
CVE References: CVE-2015-3622,CVE-2016-4008
Sources used:
openSUSE 13.2 (src):    libtasn1-3.7-2.7.1
Comment 10 Swamp Workflow Management 2016-06-16 17:08:39 UTC
SUSE-SU-2016:1600-1: An update that solves two vulnerabilities and has one errata is now available.

Category: security (moderate)
Bug References: 929414,961491,982779
CVE References: CVE-2015-3622,CVE-2016-4008
Sources used:
SUSE Linux Enterprise Software Development Kit 11-SP4 (src):    libtasn1-1.5-1.34.1
SUSE Linux Enterprise Server 11-SP4 (src):    libtasn1-1.5-1.34.1
SUSE Linux Enterprise Debuginfo 11-SP4 (src):    libtasn1-1.5-1.34.1
Comment 11 Swamp Workflow Management 2016-06-16 17:09:12 UTC
SUSE-SU-2016:1601-1: An update that solves two vulnerabilities and has one errata is now available.

Category: security (moderate)
Bug References: 929414,961491,982779
CVE References: CVE-2015-3622,CVE-2016-4008
Sources used:
SUSE Linux Enterprise Software Development Kit 12-SP1 (src):    libtasn1-3.7-11.1
SUSE Linux Enterprise Software Development Kit 12 (src):    libtasn1-3.7-11.1
SUSE Linux Enterprise Server 12-SP1 (src):    libtasn1-3.7-11.1
SUSE Linux Enterprise Server 12 (src):    libtasn1-3.7-11.1
SUSE Linux Enterprise Desktop 12-SP1 (src):    libtasn1-3.7-11.1
SUSE Linux Enterprise Desktop 12 (src):    libtasn1-3.7-11.1
Comment 12 Swamp Workflow Management 2016-06-24 14:30:19 UTC
openSUSE-SU-2016:1674-1: An update that solves two vulnerabilities and has one errata is now available.

Category: security (moderate)
Bug References: 929414,961491,982779
CVE References: CVE-2015-3622,CVE-2016-4008
Sources used:
openSUSE Leap 42.1 (src):    libtasn1-3.7-12.1
Comment 14 Wolfgang Frisch 2020-09-24 12:23:13 UTC
Released.