ELA-1336-1 libtasn1-6 security update

denial of service vulnerability

2025-02-28
Packagelibtasn1-6
Version4.2-3+deb8u6 (jessie), 4.10-1.1+deb9u3 (stretch), 4.13-3+deb10u2 (buster)
Related CVEs CVE-2024-12133


Bing Shi discovered that certificate data with a large number of names or name constraints were handled inefficiently, which may lead to Denial of Service upon specially crafted certificates.



For Debian 10 buster, these problems have been fixed in version 4.13-3+deb10u2.

For Debian 8 jessie, these problems have been fixed in version 4.2-3+deb8u6.

For Debian 9 stretch, these problems have been fixed in version 4.10-1.1+deb9u3.

We recommend that you upgrade your libtasn1-6 packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.