Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-4209

Опубликовано: 22 дек. 2021
Источник: redhat
CVSS3: 6.5

Описание

A NULL pointer dereference flaw was found in GnuTLS. As Nettle's hash update functions internally call memcpy, providing zero-length input may cause undefined behavior. This flaw leads to a denial of service after authentication in rare circumstances.

Отчет

This issue is classified as low severity because it requires a very specific and rare set of conditions to be triggered. The vulnerability occurs only when GnuTLS is built with Guile support disabled and when an empty input (zero-length data) is passed during the TLS handshake process. The crash caused by the NULL pointer dereference is a denial of service, but it does not result in remote code execution or data leakage. Additionally, the affected code path is rarely executed in practice, as it is often replaced by optimized, accelerated implementations. Compilers may also optimize away the issue in most cases, further reducing the likelihood of exploitation.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6gnutlsOut of support scope
Red Hat Enterprise Linux 7gnutlsOut of support scope
Red Hat Enterprise Linux 8gnutlsWill not fix
Red Hat Enterprise Linux 9gnutlsNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=2044156GnuTLS: Null pointer dereference in MD_UPDATE

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
почти 3 года назад

A NULL pointer dereference flaw was found in GnuTLS. As Nettle's hash update functions internally call memcpy, providing zero-length input may cause undefined behavior. This flaw leads to a denial of service after authentication in rare circumstances.

CVSS3: 6.5
nvd
почти 3 года назад

A NULL pointer dereference flaw was found in GnuTLS. As Nettle's hash update functions internally call memcpy, providing zero-length input may cause undefined behavior. This flaw leads to a denial of service after authentication in rare circumstances.

CVSS3: 6.5
msrc
почти 3 года назад

Описание отсутствует

CVSS3: 6.5
debian
почти 3 года назад

A NULL pointer dereference flaw was found in GnuTLS. As Nettle's hash ...

suse-cvrf
больше 3 лет назад

Security update for gnutls

6.5 Medium

CVSS3