Unrated severityNVD Advisory· Published May 12, 2015· Updated May 6, 2026
CVE-2015-3622
CVE-2015-3622
Description
The _asn1_extract_der_octet function in lib/decoding.c in GNU Libtasn1 before 4.5 allows remote attackers to cause a denial of service (out-of-bounds heap read) via a crafted certificate.
Affected products
3- cpe:2.3:o:fedoraproject:fedora:21:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
14- packetstormsecurity.com/files/131711/libtasn1-Heap-Overflow.htmlnvdExploit
- seclists.org/fulldisclosure/2015/Apr/109nvdExploit
- lists.fedoraproject.org/pipermail/package-announce/2015-May/158225.htmlnvd
- lists.opensuse.org/opensuse-updates/2015-08/msg00014.htmlnvd
- lists.opensuse.org/opensuse-updates/2016-06/msg00047.htmlnvd
- lists.opensuse.org/opensuse-updates/2016-06/msg00097.htmlnvd
- www.debian.org/security/2015/dsa-3256nvd
- www.mandriva.com/security/advisoriesnvd
- www.securityfocus.com/bid/74419nvd
- www.securitytracker.com/id/1032246nvd
- www.ubuntu.com/usn/USN-2604-1nvd
- access.redhat.com/errata/RHSA-2017:1860nvd
- lists.gnu.org/archive/html/help-libtasn1/2015-04/msg00000.htmlnvd
- security.gentoo.org/glsa/201509-04nvd
News mentions
0No linked articles in our index yet.