GnuTLS ECC Certificate Processing Vulnerability
RISK: Medium Risk
TYPE: Security software and application - Security Software & Appliance
A vulnerability has been identified in GnuTLS. A remote user can cause denial of service conditions.
A remote user can send a specially crafted Elliptic Curve Cryptography (ECC) certificate or certificate signing request (CSR) that, when processed by the target application, will trigger a heap corruption error and cause the application to crash.
The error occurs when printing information (e.g., key ID) about the public key.
Impact
- Denial of Service
System / Technologies affected
- Versions prior to 3.1.28, 3.2.20, 3.3.10
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- The vendor has issued a fix (3.1.28, 3.2.20, 3.3.10).
Vulnerability Identifier
Source
Related Link
Share with