The libtasn1 library, in its 4.7 version, can loop for a long time or indefinitely when it is used to parse DER representations of X509 certificates, leading to a denial of service. Some of these loops may in addition increase heap or stack usage, leading to more issues. References (with reproducer): http://seclists.org/oss-sec/2016/q2/51
Created libtasn1 tracking bugs for this issue: Affects: fedora-all [bug 1325968]
Created mingw-libtasn1 tracking bugs for this issue: Affects: fedora-all [bug 1325969] Affects: epel-7 [bug 1325970]
CVE assignment: http://seclists.org/oss-sec/2016/q2/66
libtasn1-4.8-1.fc24 has been pushed to the Fedora 24 stable repository. If problems still persist, please make note of it in this bug report.
libtasn1-4.8-1.fc23 has been pushed to the Fedora 23 stable repository. If problems still persist, please make note of it in this bug report.
libtasn1-4.8-1.fc22 has been pushed to the Fedora 22 stable repository. If problems still persist, please make note of it in this bug report.
Upstream commit: http://git.savannah.gnu.org/gitweb/?p=libtasn1.git;a=commit;h=f435825c0f527a8e52e6ffbc3ad0bc60531d537e