Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6hj5-4cv5-f46x

Опубликовано: 27 мая 2026
Источник: github
Github: Не прошло ревью
CVSS3: 8.2

Описание

A flaw was found in libgnutls. A remote attacker, by sending an extremely short premaster secret during an RSA key exchange to a server using an RSA key backed by a PKCS#11 token, could trigger a short heap overread. This memory corruption vulnerability could lead to information disclosure.

A flaw was found in libgnutls. A remote attacker, by sending an extremely short premaster secret during an RSA key exchange to a server using an RSA key backed by a PKCS#11 token, could trigger a short heap overread. This memory corruption vulnerability could lead to information disclosure.

EPSS

Процентиль: 51%
0.00727
Низкий

8.2 High

CVSS3

Дефекты

CWE-126
CWE-1284

Связанные уязвимости

CVSS3: 8.2
ubuntu
2 месяца назад

A flaw was found in libgnutls. A remote attacker, by sending an extremely short premaster secret during an RSA key exchange to a server using an RSA key backed by a PKCS#11 token, could trigger a short heap overread. This memory corruption vulnerability could lead to information disclosure.

CVSS3: 8.2
redhat
3 месяца назад

A flaw was found in libgnutls. A remote attacker, by sending an extremely short premaster secret during an RSA key exchange to a server using an RSA key backed by a PKCS#11 token, could trigger a short heap overread. This memory corruption vulnerability could lead to information disclosure.

CVSS3: 8.2
nvd
2 месяца назад

A flaw was found in libgnutls. A remote attacker, by sending an extremely short premaster secret during an RSA key exchange to a server using an RSA key backed by a PKCS#11 token, could trigger a short heap overread. This memory corruption vulnerability could lead to information disclosure.

CVSS3: 8.2
msrc
около 2 месяцев назад

Gnutls: gnutls: information disclosure via heap overread in rsa key exchange

CVSS3: 8.2
debian
2 месяца назад

A flaw was found in libgnutls. A remote attacker, by sending an extrem ...

EPSS

Процентиль: 51%
0.00727
Низкий

8.2 High

CVSS3

Дефекты

CWE-126
CWE-1284