Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2011-4128

Опубликовано: 08 дек. 2011
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 4.3

Описание

Buffer overflow in the gnutls_session_get_data function in lib/gnutls_session.c in GnuTLS 2.12.x before 2.12.14 and 3.x before 3.0.7, when used on a client that performs nonstandard session resumption, allows remote TLS servers to cause a denial of service (application crash) via a large SessionTicket.

РелизСтатусПримечание
devel

DNE

hardy

released

2.0.4-1ubuntu2.7
lucid

DNE

maverick

DNE

natty

DNE

oneiric

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

not-affected

2.12.14-5ubuntu2
hardy

DNE

lucid

released

2.8.5-2ubuntu0.1
maverick

released

2.8.6-1ubuntu0.1
natty

released

2.8.6-1ubuntu2.1
oneiric

released

2.10.5-1ubuntu3.1
upstream

released

2.12.14

Показывать по

EPSS

Процентиль: 79%
0.01319
Низкий

4.3 Medium

CVSS2

Связанные уязвимости

redhat
почти 14 лет назад

Buffer overflow in the gnutls_session_get_data function in lib/gnutls_session.c in GnuTLS 2.12.x before 2.12.14 and 3.x before 3.0.7, when used on a client that performs nonstandard session resumption, allows remote TLS servers to cause a denial of service (application crash) via a large SessionTicket.

nvd
больше 13 лет назад

Buffer overflow in the gnutls_session_get_data function in lib/gnutls_session.c in GnuTLS 2.12.x before 2.12.14 and 3.x before 3.0.7, when used on a client that performs nonstandard session resumption, allows remote TLS servers to cause a denial of service (application crash) via a large SessionTicket.

debian
больше 13 лет назад

Buffer overflow in the gnutls_session_get_data function in lib/gnutls_ ...

github
больше 3 лет назад

Buffer overflow in the gnutls_session_get_data function in lib/gnutls_session.c in GnuTLS 2.12.x before 2.12.14 and 3.x before 3.0.7, when used on a client that performs nonstandard session resumption, allows remote TLS servers to cause a denial of service (application crash) via a large SessionTicket.

oracle-oval
больше 13 лет назад

ELSA-2012-0429: gnutls security update (IMPORTANT)

EPSS

Процентиль: 79%
0.01319
Низкий

4.3 Medium

CVSS2