2 Commits

Author SHA256 Message Date
b1e45ba187 Accepting request 1326303 from security:tls
OBS-URL: https://build.opensuse.org/request/show/1326303
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/libtasn1?expand=0&rev=53
2026-01-12 09:16:00 +00:00
10a21929a9 - Update to libtasn1 4.21.0: [bsc#1256341, CVE-2025-13151]
* Undocumented asn1Decoding --debug flag removed.
  * Code coverage for src/ went from 35% to 82%.
  * Fix of ASN.1 typo in manual.
  * NEWS renamed to NEWS.md and uses markdown syntax.
  * Update gnulib files and various build/maintenance fixes.
  * Fix for vulnerability CVE-2025-13151 Stack-based buffer overflow:
    - libtasn1: stack-based buffer overflow in asn1_expend_octet_string()

OBS-URL: https://build.opensuse.org/package/show/security:tls/libtasn1?expand=0&rev=21
2026-01-09 09:40:07 +00:00
6 changed files with 40 additions and 28 deletions

Binary file not shown.

View File

@@ -1,22 +0,0 @@
-----BEGIN PGP SIGNATURE-----
iQNTBAAWCgL7FiEEo8ychwudMQq61M8vUXIrCP5HRaIFAmeksWHCHCYAmDMEXJLO
tBYJKwYBBAHaRw8BAQdACIcrZIvhrxDBkK9fV+QlTmXxo2naObDuGtw58YaxlOu0
JVNpbW9uIEpvc2Vmc3NvbiA8c2ltb25Aam9zZWZzc29uLm9yZz6IlgQTFggAPgIb
AwULCQgHAgYVCAkKCwIEFgIDAQIeAQIXgBYhBLHSvRN1vst4TPT4xNc89jjFPAa+
BQJl/YgIBQkLehFUAAoJENc89jjFPAa+CboA+wUa06RD5e5VTCxvSWtPS75Wq2qB
eYGZnf0jvUMxa2n4AP4xkUeAPPnNuMsTm2fsFCDIGaEM2Yn6Vb2huzzT1Fw/BLgz
BFySz4EWCSsGAQQB2kcPAQEHQOxTCIOaeXAxI2hIX4HK9bQTpNVei708oNr1Klm8
qCGKiPUEGBYIACYCGwIWIQSx0r0Tdb7LeEz0+MTXPPY4xTwGvgUCZf2IKwUJC3oQ
qgCBdiAEGRYIAB0WIQSjzJyHC50xCrrUzy9RcisI/kdFogUCXJLPgQAKCRBRcisI
/kdFoqdMAQCgH45aseZgIrwKOvUOA9QfsmeE8GZHYNuFHmM9FEQS6AD6A4x5aYvo
Y6lo98pgtw2HPDhmcCXFItjXCrV4A0GmJA4JENc89jjFPAa+GcYA/26YQY05bLtn
XiIjTiAzrGQrRXxTHPA8Av7TDFHvIetWAP9sHSoU8OfTwmTiEnGwLlsV7QJclZg3
YNz/Ypcp9TqQBrg4BFySz2oSCisGAQQBl1UBBQEBB0AxlRumDW6nZY7A+VCfek9V
pEx6PJmdJyYPt3lNHMd6HAMBCAeIfgQYFggAJgIbDBYhBLHSvRN1vst4TPT4xNc8
9jjFPAa+BQJl/YgwBQkLehDGAAoJENc89jjFPAa+phoA/jrDqIrl/55vUMBhIQv+
TP635d2iCTEnyFmbUcP9+gh6APoDsXalVd2cOGxQtSC+TF8PkZMn1TLkJKAjVxr+
xx40AgAKCRBRcisI/kdFok6DAP9PaJmARJKk05qvNQdGbfn2LGqiUQpifZtSktP/
LSl/1AD/Sh1QtFKGUtS1+fMRDMwProNEGpwf1TvVuaol1TC9IQk=
=Ghwk
-----END PGP SIGNATURE-----

BIN
libtasn1-4.21.0.tar.gz LFS Normal file

Binary file not shown.

View File

@@ -0,0 +1,22 @@
-----BEGIN PGP SIGNATURE-----
iQNTBAAWCgL7FiEEo8ychwudMQq61M8vUXIrCP5HRaIFAmlftBDCHCYAmDMEXJLO
tBYJKwYBBAHaRw8BAQdACIcrZIvhrxDBkK9fV+QlTmXxo2naObDuGtw58YaxlOu0
JVNpbW9uIEpvc2Vmc3NvbiA8c2ltb25Aam9zZWZzc29uLm9yZz6IlgQTFggAPgIb
AwULCQgHAgYVCAkKCwIEFgIDAQIeAQIXgBYhBLHSvRN1vst4TPT4xNc89jjFPAa+
BQJn0XQkBQkNZGbwAAoJENc89jjFPAa+BtIA/iR73CfBurG9y8pASh3cbGOMHpDZ
fMAtosu6jbpO69GHAP4p7l57d+iVty2VQMsx+3TCSAvZkpr4P/FuTzZ8JZe8Brgz
BFySz4EWCSsGAQQB2kcPAQEHQOxTCIOaeXAxI2hIX4HK9bQTpNVei708oNr1Klm8
qCGKiPUEGBYIACYCGwIWIQSx0r0Tdb7LeEz0+MTXPPY4xTwGvgUCZ9F0SgUJDWRm
SQCBdiAEGRYIAB0WIQSjzJyHC50xCrrUzy9RcisI/kdFogUCXJLPgQAKCRBRcisI
/kdFoqdMAQCgH45aseZgIrwKOvUOA9QfsmeE8GZHYNuFHmM9FEQS6AD6A4x5aYvo
Y6lo98pgtw2HPDhmcCXFItjXCrV4A0GmJA4JENc89jjFPAa+wUUBAO64fbZek6FP
lRK0DrlWsrjCXuLi6PUxyzCAY6lG2nhUAQC6qobB9mkZlZ0qihy1x4JRtflqFcqq
T9n7iUZkCDIiDbg4BFySz2oSCisGAQQBl1UBBQEBB0AxlRumDW6nZY7A+VCfek9V
pEx6PJmdJyYPt3lNHMd6HAMBCAeIfgQYFggAJgIbDBYhBLHSvRN1vst4TPT4xNc8
9jjFPAa+BQJn0XTSBQkNZGboAAoJENc89jjFPAa+0M0BAPPRq73kLnHYNDMniVBO
zUdi2XeF32idjEWWfjvyIJUOAP4wZ+ALxIehis3Uw2BzGZE6ttXQ2Q+DeCJO3TPp
IqaXDAAKCRBRcisI/kdFoqEhAP46uWEuAJnFTbnr5xOVzplScwK6+eUFHHRzM3uR
YtvZEwD/Wla0FSPHVAI5ZcCxeMkaTzgvL6BD/uitMJBSUqmrUQQ=
=D7Yo
-----END PGP SIGNATURE-----

View File

@@ -1,3 +1,15 @@
-------------------------------------------------------------------
Fri Jan 9 08:30:30 UTC 2026 - Pedro Monreal <pmonreal@suse.com>
- Update to libtasn1 4.21.0: [bsc#1256341, CVE-2025-13151]
* Undocumented asn1Decoding --debug flag removed.
* Code coverage for src/ went from 35% to 82%.
* Fix of ASN.1 typo in manual.
* NEWS renamed to NEWS.md and uses markdown syntax.
* Update gnulib files and various build/maintenance fixes.
* Fix for vulnerability CVE-2025-13151 Stack-based buffer overflow:
- libtasn1: stack-based buffer overflow in asn1_expend_octet_string()
-------------------------------------------------------------------
Thu Feb 6 20:31:51 UTC 2025 - Andreas Stieger <andreas.stieger@gmx.de>

View File

@@ -1,7 +1,7 @@
#
# spec file for package libtasn1
#
# Copyright (c) 2022 SUSE LLC
# Copyright (c) 2026 SUSE LLC and contributors
# Copyright (c) 2025 Andreas Stieger <Andreas.Stieger@gmx.de>
#
# All modifications and additions to the file contributed by third parties
@@ -19,7 +19,7 @@
%define somajor 6
Name: libtasn1
Version: 4.20.0
Version: 4.21.0
Release: 0
Summary: ASN.1 parsing library
License: GFDL-1.3-or-later AND GPL-3.0-or-later AND LGPL-2.1-or-later
@@ -94,7 +94,7 @@ find %{buildroot} -type f -name "*.la" -delete -print
%files devel
%license COPYING.LESSERv2
%doc NEWS README THANKS
%doc NEWS.md README THANKS
%{_includedir}/*.h
%{_libdir}/*.so
%{_libdir}/pkgconfig/libtasn1.pc