5

CVE-2013-4487

Exploit

Off-by-one error in the dane_raw_tlsa in the DANE library (libdane) in GnuTLS 3.1.x before 3.1.16 and 3.2.x before 3.2.6 allows remote servers to cause a denial of service (memory corruption) via a response with more than four DANE entries.  NOTE: this issue is due to an incomplete fix for CVE-2013-4466.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
GnuGnutls Version3.2.0
GnuGnutls Version3.2.1
GnuGnutls Version3.2.2
GnuGnutls Version3.2.3
GnuGnutls Version3.2.4
GnuGnutls Version3.2.5
GnuGnutls Version3.1.0
GnuGnutls Version3.1.1
GnuGnutls Version3.1.2
GnuGnutls Version3.1.3
GnuGnutls Version3.1.4
GnuGnutls Version3.1.5
GnuGnutls Version3.1.6
GnuGnutls Version3.1.7
GnuGnutls Version3.1.8
GnuGnutls Version3.1.9
GnuGnutls Version3.1.10
GnuGnutls Version3.1.11
GnuGnutls Version3.1.12
GnuGnutls Version3.1.13
GnuGnutls Version3.1.14
GnuGnutls Version3.1.15
OpensuseOpensuse Version13.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.34% 0.535
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P