Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2025-32990

Опубликовано: 10 июл. 2025
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 6.5

Описание

A heap-buffer-overflow (off-by-one) flaw was found in the GnuTLS software in the template parsing logic within the certtool utility. When it reads certain settings from a template file, it allows an attacker to cause an out-of-bounds (OOB) NULL pointer write, resulting in memory corruption and a denial-of-service (DoS) that could potentially crash the system.

РелизСтатусПримечание
devel

released

3.8.9-3ubuntu1
esm-infra/bionic

released

3.5.18-1ubuntu1.6+esm2
esm-infra/focal

released

3.6.13-2ubuntu1.12+esm1
esm-infra/xenial

released

3.4.10-4ubuntu1.9+esm2
fips-preview/jammy

needs-triage

fips-updates/jammy

released

3.7.3-4ubuntu1.7+Fips1
fips-updates/noble

released

3.8.3-1.1ubuntu3.4+Fips1
jammy

released

3.7.3-4ubuntu1.7
noble

released

3.8.3-1.1ubuntu3.4
oracular

ignored

end of life, was needs-triage

Показывать по

EPSS

Процентиль: 37%
0.00155
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
redhat
6 месяцев назад

A heap-buffer-overflow (off-by-one) flaw was found in the GnuTLS software in the template parsing logic within the certtool utility. When it reads certain settings from a template file, it allows an attacker to cause an out-of-bounds (OOB) NULL pointer write, resulting in memory corruption and a denial-of-service (DoS) that could potentially crash the system.

CVSS3: 6.5
nvd
6 месяцев назад

A heap-buffer-overflow (off-by-one) flaw was found in the GnuTLS software in the template parsing logic within the certtool utility. When it reads certain settings from a template file, it allows an attacker to cause an out-of-bounds (OOB) NULL pointer write, resulting in memory corruption and a denial-of-service (DoS) that could potentially crash the system.

CVSS3: 6.5
msrc
4 месяца назад

Gnutls: vulnerability in gnutls certtool template parsing

CVSS3: 6.5
debian
6 месяцев назад

A heap-buffer-overflow (off-by-one) flaw was found in the GnuTLS softw ...

suse-cvrf
5 месяцев назад

Security update for gnutls

EPSS

Процентиль: 37%
0.00155
Низкий

6.5 Medium

CVSS3