Gnu

Gnutls

73 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.63%
  • Veröffentlicht 10.06.2014 14:55:10
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The gnutls_x509_dn_oid_name function in lib/x509/common.c in GnuTLS 3.0 before 3.1.20 and 3.2.x before 3.2.10 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted X.509 certificate, related to a missing LDAP d...

  • EPSS 8.67%
  • Veröffentlicht 05.06.2014 20:55:06
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The (1) asn1_read_value_type and (2) asn1_read_value functions in GNU Libtasn1 before 3.6 allows context-dependent attackers to cause a denial of service (NULL pointer dereference and crash) via a NULL value in an ivalue argument.

  • EPSS 10.74%
  • Veröffentlicht 05.06.2014 20:55:06
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The asn1_get_bit_der function in GNU Libtasn1 before 3.6 does not properly report an error when a negative bit length is identified, which allows context-dependent attackers to cause out-of-bounds access via crafted ASN.1 data.

  • EPSS 6.83%
  • Veröffentlicht 05.06.2014 20:55:06
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Multiple unspecified vulnerabilities in the DER decoder in GNU Libtasn1 before 3.6, as used in GnuTLS, allow remote attackers to cause a denial of service (out-of-bounds read) via crafted ASN.1 data.

Exploit
  • EPSS 13.72%
  • Veröffentlicht 03.06.2014 14:55:10
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Buffer overflow in the read_server_hello function in lib/gnutls_handshake.c in GnuTLS before 3.1.25, 3.2.x before 3.2.15, and 3.3.x before 3.3.4 allows remote servers to cause a denial of service (memory corruption) or possibly execute arbitrary code...

Exploit
  • EPSS 0.23%
  • Veröffentlicht 07.03.2014 00:10:57
  • Zuletzt bearbeitet 06.05.2026 22:30:45

lib/x509/verify.c in GnuTLS before 3.1.21 and 3.2.x before 3.2.11 treats version 1 X.509 certificates as intermediate CAs, which allows remote attackers to bypass intended restrictions by leveraging a X.509 V1 certificate from a trusted CA to issue n...

  • EPSS 4.79%
  • Veröffentlicht 07.03.2014 00:10:53
  • Zuletzt bearbeitet 06.05.2026 22:30:45

lib/x509/verify.c in GnuTLS before 3.1.22 and 3.2.x before 3.2.12 does not properly handle unspecified errors when verifying X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers via a crafted certificate.

Exploit
  • EPSS 0.85%
  • Veröffentlicht 07.03.2014 00:10:53
  • Zuletzt bearbeitet 06.05.2026 22:30:45

GnuTLS before 2.7.6, when the GNUTLS_VERIFY_ALLOW_X509_V1_CA_CRT flag is not enabled, treats version 1 X.509 certificates as intermediate CAs, which allows remote attackers to bypass intended restrictions by leveraging a X.509 V1 certificate from a t...

Exploit
  • EPSS 0.34%
  • Veröffentlicht 20.11.2013 14:12:30
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Off-by-one error in the dane_raw_tlsa in the DANE library (libdane) in GnuTLS 3.1.x before 3.1.16 and 3.2.x before 3.2.6 allows remote servers to cause a denial of service (memory corruption) via a response with more than four DANE entries. NOTE: th...

  • EPSS 0.57%
  • Veröffentlicht 20.11.2013 14:12:30
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Buffer overflow in the dane_query_tlsa function in the DANE library (libdane) in GnuTLS 3.1.x before 3.1.15 and 3.2.x before 3.2.5 allows remote servers to cause a denial of service (memory corruption) via a response with more than four DANE entries.