GNU Libtasn1 4.8 released

From: Nikos Mavrogiannopoulos
Subject: GNU Libtasn1 4.8 released
Date: Mon, 11 Apr 2016 08:42:18 +0200

GNU Libtasn1 is a standalone library written in C for manipulating
ASN.1 objects including DER/BER encoding/decoding.  GNU Libtasn1 is
used by GnuTLS to handle X.509 structures and by GNU Shishi to handle
Kerberos V5 structures.

This release among other improvements prevents of a possible DoS
(infinite loop) in the decoding of BER structures.

* Noteworthy changes in release 4.8 (released 2016-04-11) [stable]
- Fixes to avoid reliance on C undefined behavior.
- Fixes to avoid an infinite recursion when decoding without
  the ASN1_DECODE_FLAG_STRICT_DER flag. Reported by Pascal Cuoq.
- Combined all the BER octet string decoding functions to a single
  one based on asn1_decode_simple_ber().


Here are the compressed sources:

Here are GPG detached signatures:

If you need help to use Libtasn1, or want to help others, you are
invited to join the help-libtasn1 mailing list, see:

All manuals are available from:

Direct links to the manual:

Direct links to the API Reference manual:

The software is cryptographically signed by the author using an
OpenPGP key identified by the following information:

pub   3104R/96865171 2008-05-04 [expires: 2028-04-29]
uid                  Nikos Mavrogiannopoulos <nmav <at>>
uid                  Nikos Mavrogiannopoulos <n.mavrogiannopoulos <at>>
sub   2048R/9013B842 2008-05-04 [expires: 2018-05-02]
sub   2048R/1404A91D 2008-05-04 [expires: 2018-05-02]


