5

CVE-2012-1573

Exploit

gnutls_cipher.c in libgnutls in GnuTLS before 2.12.17 and 3.x before 3.0.15 does not properly handle data encrypted with a block cipher, which allows remote attackers to cause a denial of service (heap memory corruption and application crash) via a crafted record, as demonstrated by a crafted GenericBlockCipher structure.

Data is provided by the National Vulnerability Database (NVD)
GnuGnutls Version <= 2.12.16
GnuGnutls Version2.0.0
GnuGnutls Version2.0.1
GnuGnutls Version2.0.2
GnuGnutls Version2.0.3
GnuGnutls Version2.0.4
GnuGnutls Version2.1.0
GnuGnutls Version2.1.1
GnuGnutls Version2.1.2
GnuGnutls Version2.1.3
GnuGnutls Version2.1.4
GnuGnutls Version2.1.5
GnuGnutls Version2.1.6
GnuGnutls Version2.1.7
GnuGnutls Version2.1.8
GnuGnutls Version2.2.0
GnuGnutls Version2.2.1
GnuGnutls Version2.2.2
GnuGnutls Version2.2.3
GnuGnutls Version2.2.4
GnuGnutls Version2.2.5
GnuGnutls Version2.3.0
GnuGnutls Version2.3.1
GnuGnutls Version2.3.2
GnuGnutls Version2.3.3
GnuGnutls Version2.3.4
GnuGnutls Version2.3.5
GnuGnutls Version2.3.6
GnuGnutls Version2.3.7
GnuGnutls Version2.3.8
GnuGnutls Version2.3.9
GnuGnutls Version2.3.10
GnuGnutls Version2.3.11
GnuGnutls Version2.4.0
GnuGnutls Version2.4.1
GnuGnutls Version2.4.2
GnuGnutls Version2.4.3
GnuGnutls Version2.5.0
GnuGnutls Version2.6.0
GnuGnutls Version2.6.1
GnuGnutls Version2.6.2
GnuGnutls Version2.6.3
GnuGnutls Version2.6.4
GnuGnutls Version2.6.5
GnuGnutls Version2.6.6
GnuGnutls Version2.7.4
GnuGnutls Version2.8.0
GnuGnutls Version2.8.1
GnuGnutls Version2.8.2
GnuGnutls Version2.8.3
GnuGnutls Version2.8.4
GnuGnutls Version2.8.5
GnuGnutls Version2.8.6
GnuGnutls Version2.10.0
GnuGnutls Version2.10.1
GnuGnutls Version2.10.2
GnuGnutls Version2.10.3
GnuGnutls Version2.10.4
GnuGnutls Version2.10.5
GnuGnutls Version2.12.0
GnuGnutls Version2.12.1
GnuGnutls Version2.12.2
GnuGnutls Version2.12.3
GnuGnutls Version2.12.4
GnuGnutls Version2.12.5
GnuGnutls Version2.12.6
GnuGnutls Version2.12.6.1
GnuGnutls Version2.12.7
GnuGnutls Version2.12.8
GnuGnutls Version2.12.9
GnuGnutls Version2.12.10
GnuGnutls Version2.12.11
GnuGnutls Version2.12.12
GnuGnutls Version2.12.13
GnuGnutls Version2.12.14
GnuGnutls Version2.12.15
GnuGnutls Version3.0
GnuGnutls Version3.0.0
GnuGnutls Version3.0.1
GnuGnutls Version3.0.2
GnuGnutls Version3.0.3
GnuGnutls Version3.0.4
GnuGnutls Version3.0.5
GnuGnutls Version3.0.6
GnuGnutls Version3.0.7
GnuGnutls Version3.0.8
GnuGnutls Version3.0.9
GnuGnutls Version3.0.10
GnuGnutls Version3.0.11
GnuGnutls Version3.0.12
GnuGnutls Version3.0.13
GnuGnutls Version3.0.14
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 10.17% 0.928
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P