VYPR
High severity8.8NVD Advisory· Published May 22, 2017· Updated May 13, 2026

CVE-2017-6891

CVE-2017-6891

Description

Two errors in the "asn1_find_node()" function (lib/parser_aux.c) within GnuTLS libtasn1 version 4.10 can be exploited to cause a stacked-based buffer overflow by tricking a user into processing a specially crafted assignments file via the e.g. asn1Coding utility.

Affected products

4
  • cpe:2.3:a:apache:bookkeeper:4.12.1:*:*:*:*:*:*:*
  • cpe:2.3:a:gnu:libtasn1:4.10:*:*:*:*:*:*:*
  • cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
  • Flexera Software LLC/GnuTLS libtasn1v5
    Range: 4.10. Other versions may also be affected.

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

9

News mentions

0

No linked articles in our index yet.