Описание
Buffer overflow in the gnutls_session_get_data function in lib/gnutls_session.c in GnuTLS 2.12.x before 2.12.14 and 3.x before 3.0.7, when used on a client that performs nonstandard session resumption, allows remote TLS servers to cause a denial of service (application crash) via a large SessionTicket.
Релиз | Статус | Примечание |
---|---|---|
devel | DNE | |
hardy | released | 2.0.4-1ubuntu2.7 |
lucid | DNE | |
maverick | DNE | |
natty | DNE | |
oneiric | DNE | |
upstream | needs-triage |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
devel | not-affected | 2.12.14-5ubuntu2 |
hardy | DNE | |
lucid | released | 2.8.5-2ubuntu0.1 |
maverick | released | 2.8.6-1ubuntu0.1 |
natty | released | 2.8.6-1ubuntu2.1 |
oneiric | released | 2.10.5-1ubuntu3.1 |
upstream | released | 2.12.14 |
Показывать по
EPSS
4.3 Medium
CVSS2
Связанные уязвимости
Buffer overflow in the gnutls_session_get_data function in lib/gnutls_session.c in GnuTLS 2.12.x before 2.12.14 and 3.x before 3.0.7, when used on a client that performs nonstandard session resumption, allows remote TLS servers to cause a denial of service (application crash) via a large SessionTicket.
Buffer overflow in the gnutls_session_get_data function in lib/gnutls_session.c in GnuTLS 2.12.x before 2.12.14 and 3.x before 3.0.7, when used on a client that performs nonstandard session resumption, allows remote TLS servers to cause a denial of service (application crash) via a large SessionTicket.
Buffer overflow in the gnutls_session_get_data function in lib/gnutls_ ...
Buffer overflow in the gnutls_session_get_data function in lib/gnutls_session.c in GnuTLS 2.12.x before 2.12.14 and 3.x before 3.0.7, when used on a client that performs nonstandard session resumption, allows remote TLS servers to cause a denial of service (application crash) via a large SessionTicket.
EPSS
4.3 Medium
CVSS2