Gnu

Gnutls

68 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.23%
  • Published 07.03.2014 00:10:57
  • Last modified 12.04.2025 10:46:40

lib/x509/verify.c in GnuTLS before 3.1.21 and 3.2.x before 3.2.11 treats version 1 X.509 certificates as intermediate CAs, which allows remote attackers to bypass intended restrictions by leveraging a X.509 V1 certificate from a trusted CA to issue n...

  • EPSS 3.38%
  • Published 07.03.2014 00:10:53
  • Last modified 12.04.2025 10:46:40

lib/x509/verify.c in GnuTLS before 3.1.22 and 3.2.x before 3.2.12 does not properly handle unspecified errors when verifying X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers via a crafted certificate.

Exploit
  • EPSS 1.37%
  • Published 07.03.2014 00:10:53
  • Last modified 12.04.2025 10:46:40

GnuTLS before 2.7.6, when the GNUTLS_VERIFY_ALLOW_X509_V1_CA_CRT flag is not enabled, treats version 1 X.509 certificates as intermediate CAs, which allows remote attackers to bypass intended restrictions by leveraging a X.509 V1 certificate from a t...

Exploit
  • EPSS 0.34%
  • Published 20.11.2013 14:12:30
  • Last modified 11.04.2025 00:51:21

Off-by-one error in the dane_raw_tlsa in the DANE library (libdane) in GnuTLS 3.1.x before 3.1.16 and 3.2.x before 3.2.6 allows remote servers to cause a denial of service (memory corruption) via a response with more than four DANE entries. NOTE: th...

  • EPSS 0.57%
  • Published 20.11.2013 14:12:30
  • Last modified 11.04.2025 00:51:21

Buffer overflow in the dane_query_tlsa function in the DANE library (libdane) in GnuTLS 3.1.x before 3.1.15 and 3.2.x before 3.2.5 allows remote servers to cause a denial of service (memory corruption) via a response with more than four DANE entries.

  • EPSS 8.99%
  • Published 03.07.2013 18:55:01
  • Last modified 11.04.2025 00:51:21

The _gnutls_ciphertext2compressed function in lib/gnutls_cipher.c in GnuTLS 2.12.23 allows remote attackers to cause a denial of service (buffer over-read and crash) via a crafted padding length. NOTE: this might be due to an incorrect fix for CVE-2...

Exploit
  • EPSS 0.85%
  • Published 08.02.2013 19:55:01
  • Last modified 11.04.2025 00:51:21

The TLS implementation in GnuTLS before 2.12.23, 3.0.x before 3.0.28, and 3.1.x before 3.1.7 does not properly consider timing side-channel attacks on a noncompliant MAC check operation during the processing of malformed CBC padding, which allows rem...

Exploit
  • EPSS 10.17%
  • Published 26.03.2012 19:55:01
  • Last modified 11.04.2025 00:51:21

gnutls_cipher.c in libgnutls in GnuTLS before 2.12.17 and 3.x before 3.0.15 does not properly handle data encrypted with a block cipher, which allows remote attackers to cause a denial of service (heap memory corruption and application crash) via a c...

Exploit
  • EPSS 12.72%
  • Published 26.03.2012 19:55:01
  • Last modified 11.04.2025 00:51:21

The asn1_get_length_der function in decoding.c in GNU Libtasn1 before 2.12, as used in GnuTLS before 3.0.16 and other products, does not properly handle certain large length values, which allows remote attackers to cause a denial of service (heap mem...

  • EPSS 1.64%
  • Published 13.03.2012 22:55:03
  • Last modified 11.04.2025 00:51:21

Double free vulnerability in libgnutls in GnuTLS before 3.0.14 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted certificate list.