Security update for libtasn1
This update for libtasn1 fixes the following issues: Security issue fixed: - CVE-2018-1000654: Fixed a denial of service in the asn1 parser (bsc#1105435). - CVE-2017-6891: Added safety check to fix a stack overflow issue (bsc#1040621). - CVE-2021-46848: Fixed off-by-one array size check that affects asn1_encode_simple_der (bsc#1204690)
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for libtasn1 fixes the following issues: Security issue fixed: - CVE-2018-1000654: Fixed a denial of service in the asn1 parser (bsc#1105435). - CVE-2017-6891: Added safety check to fix a stack overflow issue (bsc#1040621). - CVE-2021-46848: Fixed off-by-one array size check that affects asn1_encode_simple_der (bsc#1204690)
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1040621
- https://bugzilla.suse.com/1105435
- https://bugzilla.suse.com/1204690
- https://www.suse.com/security/cve/CVE-2017-6891
- https://www.suse.com/security/cve/CVE-2018-1000654
- https://www.suse.com/security/cve/CVE-2021-46848
- https://www.suse.com/support/update/announcement/2022/suse-su-20223797-1/