Debian Security Advisory

DSA-3861-1 libtasn1-6 -- security update

Date Reported:
24 May 2017
Affected Packages:
libtasn1-6
Vulnerable:
Yes
Security database references:
In the Debian bugtracking system: Bug 863186.
In Mitre's CVE dictionary: CVE-2017-6891.
More information:

Jakub Jirasek of Secunia Research discovered that libtasn1, a library used to handle Abstract Syntax Notation One structures, did not properly validate its input. This would allow an attacker to cause a crash by denial-of-service, or potentially execute arbitrary code, by tricking a user into processing a maliciously crafted assignments file.

For the stable distribution (jessie), this problem has been fixed in version 4.2-3+deb8u3.

We recommend that you upgrade your libtasn1-6 packages.