Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2014-3466

Опубликовано: 03 июн. 2014
Источник: debian
EPSS Средний

Описание

Buffer overflow in the read_server_hello function in lib/gnutls_handshake.c in GnuTLS before 3.1.25, 3.2.x before 3.2.15, and 3.3.x before 3.3.4 allows remote servers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a long session id in a ServerHello message.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
gnutls26fixed2.12.23-16package
gnutls28fixed3.2.15-1package
gnutls26fixed2.8.6-1+squeeze4squeezepackage

Примечания

  • http://radare.today/technical-analysis-of-the-gnutls-hello-vulnerability/

EPSS

Процентиль: 96%
0.23263
Средний

Связанные уязвимости

ubuntu
около 11 лет назад

Buffer overflow in the read_server_hello function in lib/gnutls_handshake.c in GnuTLS before 3.1.25, 3.2.x before 3.2.15, and 3.3.x before 3.3.4 allows remote servers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a long session id in a ServerHello message.

redhat
около 11 лет назад

Buffer overflow in the read_server_hello function in lib/gnutls_handshake.c in GnuTLS before 3.1.25, 3.2.x before 3.2.15, and 3.3.x before 3.3.4 allows remote servers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a long session id in a ServerHello message.

nvd
около 11 лет назад

Buffer overflow in the read_server_hello function in lib/gnutls_handshake.c in GnuTLS before 3.1.25, 3.2.x before 3.2.15, and 3.3.x before 3.3.4 allows remote servers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a long session id in a ServerHello message.

github
около 3 лет назад

Buffer overflow in the read_server_hello function in lib/gnutls_handshake.c in GnuTLS before 3.1.25, 3.2.x before 3.2.15, and 3.3.x before 3.3.4 allows remote servers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a long session id in a ServerHello message.

oracle-oval
около 11 лет назад

ELSA-2014-0595: gnutls security update (IMPORTANT)

EPSS

Процентиль: 96%
0.23263
Средний