Skip to main content

GnuTLS DistinguishedName Decoding Vulnerability

Last Update Date: 12 Aug 2015 12:02 Release Date: 12 Aug 2015 3310 Views

RISK: Medium Risk

TYPE: Security software and application - Security Software & Appliance

TYPE: Security Software & Appliance

A vulnerability has been identified in GnuTLS. A remote user can cause the target service to crash.

 

A remote user can create a certificate with a specially crafted DistinguishedName (DN) entry that, when decoded by the target application, will trigger a double free memory error and cause the application to crash.


Impact

  • Denial of Service

System / Technologies affected

  • Versions prior to 3.3.17 and 3.4.4

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

  • The vendor has issued a fix (3.3.17, 3.4.4).

Vulnerability Identifier

  • No CVE information is available

Source


Related Link

Previous

Mozilla Firefox Multiple Vulnerabilities

Next

Android AOSP SMS Messaging App Multiple Vulnerabilities