Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2016-7444

Опубликовано: 27 сент. 2016
Источник: nvd
CVSS3: 7.5
CVSS2: 5
EPSS Низкий

Описание

The gnutls_ocsp_resp_check_crt function in lib/x509/ocsp.c in GnuTLS before 3.4.15 and 3.5.x before 3.5.4 does not verify the serial length of an OCSP response, which might allow remote attackers to bypass an intended certificate validation mechanism via vectors involving trailing bytes left by gnutls_malloc.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:gnu:gnutls:*:*:*:*:*:*:*:*
Версия до 3.4.14 (включая)
cpe:2.3:a:gnu:gnutls:3.5.0:*:*:*:*:*:*:*
cpe:2.3:a:gnu:gnutls:3.5.1:*:*:*:*:*:*:*
cpe:2.3:a:gnu:gnutls:3.5.2:*:*:*:*:*:*:*
cpe:2.3:a:gnu:gnutls:3.5.3:*:*:*:*:*:*:*

EPSS

Процентиль: 77%
0.01021
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-264

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 9 лет назад

The gnutls_ocsp_resp_check_crt function in lib/x509/ocsp.c in GnuTLS before 3.4.15 and 3.5.x before 3.5.4 does not verify the serial length of an OCSP response, which might allow remote attackers to bypass an intended certificate validation mechanism via vectors involving trailing bytes left by gnutls_malloc.

CVSS3: 5.3
redhat
около 9 лет назад

The gnutls_ocsp_resp_check_crt function in lib/x509/ocsp.c in GnuTLS before 3.4.15 and 3.5.x before 3.5.4 does not verify the serial length of an OCSP response, which might allow remote attackers to bypass an intended certificate validation mechanism via vectors involving trailing bytes left by gnutls_malloc.

CVSS3: 7.5
debian
около 9 лет назад

The gnutls_ocsp_resp_check_crt function in lib/x509/ocsp.c in GnuTLS b ...

CVSS3: 7.5
github
больше 3 лет назад

The gnutls_ocsp_resp_check_crt function in lib/x509/ocsp.c in GnuTLS before 3.4.15 and 3.5.x before 3.5.4 does not verify the serial length of an OCSP response, which might allow remote attackers to bypass an intended certificate validation mechanism via vectors involving trailing bytes left by gnutls_malloc.

suse-cvrf
почти 9 лет назад

Security update for gnutls

EPSS

Процентиль: 77%
0.01021
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-264