Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-45p2-c2m2-2656

Опубликовано: 27 мая 2026
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

A flaw was found in gnutls. An off-by-one error exists in the PKCS#12 bag element bounds check. This vulnerability allows an remote attacker to write past the internal array of a PKCS#12 bag when appending to a bag that already contains 32 elements. This memory corruption could lead to a denial of service (DoS) or potentially other unspecified impacts.

A flaw was found in gnutls. An off-by-one error exists in the PKCS#12 bag element bounds check. This vulnerability allows an remote attacker to write past the internal array of a PKCS#12 bag when appending to a bag that already contains 32 elements. This memory corruption could lead to a denial of service (DoS) or potentially other unspecified impacts.

EPSS

Процентиль: 50%
0.00727
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-193

Связанные уязвимости

CVSS3: 5.3
ubuntu
2 месяца назад

A flaw was found in gnutls. An off-by-one error exists in the PKCS#12 bag element bounds check. This vulnerability allows an remote attacker to write past the internal array of a PKCS#12 bag when appending to a bag that already contains 32 elements. This memory corruption could lead to a denial of service (DoS) or potentially other unspecified impacts.

CVSS3: 5.3
redhat
3 месяца назад

A flaw was found in gnutls. An off-by-one error exists in the PKCS#12 bag element bounds check. This vulnerability allows an remote attacker to write past the internal array of a PKCS#12 bag when appending to a bag that already contains 32 elements. This memory corruption could lead to a denial of service (DoS) or potentially other unspecified impacts.

CVSS3: 5.3
nvd
2 месяца назад

A flaw was found in gnutls. An off-by-one error exists in the PKCS#12 bag element bounds check. This vulnerability allows an remote attacker to write past the internal array of a PKCS#12 bag when appending to a bag that already contains 32 elements. This memory corruption could lead to a denial of service (DoS) or potentially other unspecified impacts.

CVSS3: 5.3
msrc
2 месяца назад

Gnutls: gnutls: memory corruption due to off-by-one error in pkcs#12 bag handling

CVSS3: 5.3
debian
2 месяца назад

A flaw was found in gnutls. An off-by-one error exists in the PKCS#12 ...

EPSS

Процентиль: 50%
0.00727
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-193