[DSA 5863-1] libtasn1-6 security update

Salvatore Bonaccorso <[email protected]>
Newsgroups gmane.linux.debian.user.security.announce
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian Security Advisory DSA-5863-1                   [email protected]
https://www.debian.org/security/                     Salvatore Bonaccorso
February 10, 2025                     https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package        : libtasn1-6
CVE ID         : CVE-2024-12133
Debian Bug     : 1095406

Bing Shi reported a flaw in Libtasn1, a library to manage ASN.1
structures. Inefficient processing of input DER data containing a large
number of SEQUENCE OF or SET OF elements, may result in a denial of
service.

For the stable distribution (bookworm), this problem has been fixed in
version 4.19.0-2+deb12u1.

We recommend that you upgrade your libtasn1-6 packages.

For the detailed security status of libtasn1-6 please refer to its
security tracker page at:
https://security-tracker.debian.org/tracker/libtasn1-6

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: [email protected]
-----BEGIN PGP SIGNATURE-----

iQKTBAEBCgB9FiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmeqcdhfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2
NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQACgkQBUy48xND
z0QGQxAAhAOGBEToY6UHf/BGfmWOSMpWfzuIngS8/MpYCgSbmuJctTwUz25nJhM4
57cPpIhGXUl57TL7uE0YPRcuIreSb5/tq3V7CfPEDRggiVPLOr/NOcjuSvs1smOt
4uAjnCOzQ+5q8CZhwQ1UX+LOYVcbnlD+dbuS+2y0POxdINbgm0MLy01W6sEZwog/
TwuVHFgbZmJwKjSTAayxtq97qXi4ViRUqxrTDWOEmFQirhjWa8h6n0z673Yuy+2i
KJTH4ZTAlDgWG6uTd3jX0tkKKYF2+jI061iYuJg3gzqR5MTDxEXYUq2YW8bmHnAf
scg0ZF2DC19kvMQ93OKIA6plRthYG4NdHgSEluexcIyH2hj2M191e5Ufj2MHAyUd
1lyZmTIdzn4XOhk2ljLWO53hXPE8jZ/qZl9PSOAcX/rTql+jNJR8KVHmKt/va56W
dFf6dkxHA524Er5INXKjQ15VURMXX7wukCUBJQpakEdvXdX/wDtYha/pve2/BSKC
j81ozr97qRAPhvCy8/R08vbb9d2eDH8lybqBlw9ZIbC70zbOalukqgyknrVgHY2C
KkK6QbQIxc1+JcXVbeUPxiVhw4c0xSLu753hrVuv73eGiJZQYIV38wXcC/sMwO6/
Xq2+DN5wjCeM3J/uwLJVL7SO3QitzBi4ihTylrU0bsI3hO+v0iI=
=Mnty
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.