CVE-2025-32990
- EPSS 0.1%
- Veröffentlicht 10.07.2025 09:41:46
- Zuletzt bearbeitet 06.10.2025 12:15:33
A heap-buffer-overflow (off-by-one) flaw was found in the GnuTLS software in the template parsing logic within the certtool utility. When it reads certain settings from a template file, it allows an attacker to cause an out-of-bounds (OOB) NULL point...
CVE-2025-32989
- EPSS 0.03%
- Veröffentlicht 10.07.2025 08:05:26
- Zuletzt bearbeitet 06.10.2025 12:15:33
A heap-buffer-overread vulnerability was found in GnuTLS in how it handles the Certificate Transparency (CT) Signed Certificate Timestamp (SCT) extension during X.509 certificate parsing. This flaw allows a malicious user to create a certificate cont...
CVE-2025-32988
- EPSS 0.1%
- Veröffentlicht 10.07.2025 08:04:57
- Zuletzt bearbeitet 06.10.2025 12:15:33
A flaw was found in GnuTLS. A double-free vulnerability exists in GnuTLS due to incorrect ownership handling in the export logic of Subject Alternative Name (SAN) entries containing an otherName. If the type-id OID is invalid or malformed, GnuTLS wil...
CVE-2024-0567
- EPSS 1.3%
- Veröffentlicht 16.01.2024 14:15:48
- Zuletzt bearbeitet 21.11.2024 08:46:53
A vulnerability was found in GnuTLS, where a cockpit (which uses gnuTLS) rejects a certificate chain with distributed trust. This issue occurs when validating a certificate chain with cockpit-certificate-ensure. This flaw allows an unauthenticated, r...
CVE-2024-0553
- EPSS 1.03%
- Veröffentlicht 16.01.2024 12:15:45
- Zuletzt bearbeitet 21.11.2024 08:46:51
A vulnerability was found in GnuTLS. The response times to malformed ciphertexts in RSA-PSK ClientKeyExchange differ from the response times of ciphertexts with correct PKCS#1 v1.5 padding. This issue may allow a remote attacker to perform a timing s...
CVE-2023-5981
- EPSS 0.56%
- Veröffentlicht 28.11.2023 12:15:07
- Zuletzt bearbeitet 21.11.2024 08:42:54
A vulnerability was found that the response times to malformed ciphertexts in RSA-PSK ClientKeyExchange differ from response times of ciphertexts with correct PKCS#1 v1.5 padding.
CVE-2023-0361
- EPSS 1.2%
- Veröffentlicht 15.02.2023 18:15:11
- Zuletzt bearbeitet 19.03.2025 18:15:18
A timing side-channel in the handling of RSA ClientKeyExchange messages was discovered in GnuTLS. This side-channel can be sufficient to recover the key encrypted in the RSA ciphertext across a network in a Bleichenbacher style attack. To achieve a s...
CVE-2021-4209
- EPSS 0.17%
- Veröffentlicht 24.08.2022 16:15:09
- Zuletzt bearbeitet 21.11.2024 06:37:09
A NULL pointer dereference flaw was found in GnuTLS. As Nettle's hash update functions internally call memcpy, providing zero-length input may cause undefined behavior. This flaw leads to a denial of service after authentication in rare circumstances...
CVE-2022-2509
- EPSS 0.91%
- Veröffentlicht 01.08.2022 14:15:09
- Zuletzt bearbeitet 21.11.2024 07:01:08
A vulnerability found in gnutls. This security flaw happens because of a double free error occurs during verification of pkcs7 signatures in gnutls_pkcs7_verify function.
CVE-2021-20232
- EPSS 0.84%
- Veröffentlicht 12.03.2021 19:15:13
- Zuletzt bearbeitet 21.11.2024 05:46:10
A flaw was found in gnutls. A use after free issue in client_send_params in lib/ext/pre_shared_key.c may lead to memory corruption and other potential consequences.