Gnu

Gnutls

68 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.23%
  • Veröffentlicht 07.03.2014 00:10:57
  • Zuletzt bearbeitet 12.04.2025 10:46:40

lib/x509/verify.c in GnuTLS before 3.1.21 and 3.2.x before 3.2.11 treats version 1 X.509 certificates as intermediate CAs, which allows remote attackers to bypass intended restrictions by leveraging a X.509 V1 certificate from a trusted CA to issue n...

  • EPSS 3.38%
  • Veröffentlicht 07.03.2014 00:10:53
  • Zuletzt bearbeitet 12.04.2025 10:46:40

lib/x509/verify.c in GnuTLS before 3.1.22 and 3.2.x before 3.2.12 does not properly handle unspecified errors when verifying X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers via a crafted certificate.

Exploit
  • EPSS 1.37%
  • Veröffentlicht 07.03.2014 00:10:53
  • Zuletzt bearbeitet 12.04.2025 10:46:40

GnuTLS before 2.7.6, when the GNUTLS_VERIFY_ALLOW_X509_V1_CA_CRT flag is not enabled, treats version 1 X.509 certificates as intermediate CAs, which allows remote attackers to bypass intended restrictions by leveraging a X.509 V1 certificate from a t...

Exploit
  • EPSS 0.34%
  • Veröffentlicht 20.11.2013 14:12:30
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Off-by-one error in the dane_raw_tlsa in the DANE library (libdane) in GnuTLS 3.1.x before 3.1.16 and 3.2.x before 3.2.6 allows remote servers to cause a denial of service (memory corruption) via a response with more than four DANE entries. NOTE: th...

  • EPSS 0.57%
  • Veröffentlicht 20.11.2013 14:12:30
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Buffer overflow in the dane_query_tlsa function in the DANE library (libdane) in GnuTLS 3.1.x before 3.1.15 and 3.2.x before 3.2.5 allows remote servers to cause a denial of service (memory corruption) via a response with more than four DANE entries.

  • EPSS 8.99%
  • Veröffentlicht 03.07.2013 18:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The _gnutls_ciphertext2compressed function in lib/gnutls_cipher.c in GnuTLS 2.12.23 allows remote attackers to cause a denial of service (buffer over-read and crash) via a crafted padding length. NOTE: this might be due to an incorrect fix for CVE-2...

Exploit
  • EPSS 0.85%
  • Veröffentlicht 08.02.2013 19:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The TLS implementation in GnuTLS before 2.12.23, 3.0.x before 3.0.28, and 3.1.x before 3.1.7 does not properly consider timing side-channel attacks on a noncompliant MAC check operation during the processing of malformed CBC padding, which allows rem...

Exploit
  • EPSS 10.17%
  • Veröffentlicht 26.03.2012 19:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

gnutls_cipher.c in libgnutls in GnuTLS before 2.12.17 and 3.x before 3.0.15 does not properly handle data encrypted with a block cipher, which allows remote attackers to cause a denial of service (heap memory corruption and application crash) via a c...

Exploit
  • EPSS 12.72%
  • Veröffentlicht 26.03.2012 19:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The asn1_get_length_der function in decoding.c in GNU Libtasn1 before 2.12, as used in GnuTLS before 3.0.16 and other products, does not properly handle certain large length values, which allows remote attackers to cause a denial of service (heap mem...

  • EPSS 1.64%
  • Veröffentlicht 13.03.2012 22:55:03
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Double free vulnerability in libgnutls in GnuTLS before 3.0.14 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted certificate list.