Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-32990

Опубликовано: 10 июл. 2025
Источник: debian
EPSS Низкий

Описание

A heap-buffer-overflow (off-by-one) flaw was found in the GnuTLS software in the template parsing logic within the certtool utility. When it reads certain settings from a template file, it allows an attacker to cause an out-of-bounds (OOB) NULL pointer write, resulting in memory corruption and a denial-of-service (DoS) that could potentially crash the system.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
gnutls28fixed3.8.9-3package

Примечания

  • https://lists.gnupg.org/pipermail/gnutls-help/2025-July/004883.html

  • https://gitlab.com/gnutls/gnutls/-/issues/1696

  • Fixed by: https://gitlab.com/gnutls/gnutls/-/commit/408bed40c36a4cc98f0c94a818f682810f731f32 (3.8.10)

EPSS

Процентиль: 23%
0.00072
Низкий

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 1 месяца назад

A heap-buffer-overflow (off-by-one) flaw was found in the GnuTLS software in the template parsing logic within the certtool utility. When it reads certain settings from a template file, it allows an attacker to cause an out-of-bounds (OOB) NULL pointer write, resulting in memory corruption and a denial-of-service (DoS) that could potentially crash the system.

CVSS3: 6.5
redhat
около 1 месяца назад

A heap-buffer-overflow (off-by-one) flaw was found in the GnuTLS software in the template parsing logic within the certtool utility. When it reads certain settings from a template file, it allows an attacker to cause an out-of-bounds (OOB) NULL pointer write, resulting in memory corruption and a denial-of-service (DoS) that could potentially crash the system.

CVSS3: 6.5
nvd
около 1 месяца назад

A heap-buffer-overflow (off-by-one) flaw was found in the GnuTLS software in the template parsing logic within the certtool utility. When it reads certain settings from a template file, it allows an attacker to cause an out-of-bounds (OOB) NULL pointer write, resulting in memory corruption and a denial-of-service (DoS) that could potentially crash the system.

CVSS3: 6.5
msrc
около 1 месяца назад

Описание отсутствует

suse-cvrf
28 дней назад

Security update for gnutls

EPSS

Процентиль: 23%
0.00072
Низкий