Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2011-4128

Опубликовано: 07 нояб. 2011
Источник: redhat
CVSS2: 5.1
EPSS Низкий

Описание

Buffer overflow in the gnutls_session_get_data function in lib/gnutls_session.c in GnuTLS 2.12.x before 2.12.14 and 3.x before 3.0.7, when used on a client that performs nonstandard session resumption, allows remote TLS servers to cause a denial of service (application crash) via a large SessionTicket.

Отчет

This issue does not affect the version of gnutls as shipped with Red Hat Enterprise Linux 4.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 4gnutlsNot affected
Red Hat Enterprise Linux 6mingw32-gnutlsWill not fix
Red Hat Enterprise Linux 5gnutlsFixedRHSA-2012:042827.03.2012
Red Hat Enterprise Linux 6gnutlsFixedRHSA-2012:042927.03.2012

Показывать по

Дополнительная информация

Статус:

Low
https://bugzilla.redhat.com/show_bug.cgi?id=752308gnutls: buffer overflow in gnutls_session_get_data() (GNUTLS-SA-2011-2)

EPSS

Процентиль: 79%
0.01319
Низкий

5.1 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 13 лет назад

Buffer overflow in the gnutls_session_get_data function in lib/gnutls_session.c in GnuTLS 2.12.x before 2.12.14 and 3.x before 3.0.7, when used on a client that performs nonstandard session resumption, allows remote TLS servers to cause a denial of service (application crash) via a large SessionTicket.

nvd
больше 13 лет назад

Buffer overflow in the gnutls_session_get_data function in lib/gnutls_session.c in GnuTLS 2.12.x before 2.12.14 and 3.x before 3.0.7, when used on a client that performs nonstandard session resumption, allows remote TLS servers to cause a denial of service (application crash) via a large SessionTicket.

debian
больше 13 лет назад

Buffer overflow in the gnutls_session_get_data function in lib/gnutls_ ...

github
больше 3 лет назад

Buffer overflow in the gnutls_session_get_data function in lib/gnutls_session.c in GnuTLS 2.12.x before 2.12.14 and 3.x before 3.0.7, when used on a client that performs nonstandard session resumption, allows remote TLS servers to cause a denial of service (application crash) via a large SessionTicket.

oracle-oval
больше 13 лет назад

ELSA-2012-0429: gnutls security update (IMPORTANT)

EPSS

Процентиль: 79%
0.01319
Низкий

5.1 Medium

CVSS2