Skip to main content

GnuTLS ECC Certificate Processing Vulnerability

Last Update Date: 19 Nov 2014 Release Date: 13 Nov 2014 3046 Views

RISK: Medium Risk

TYPE: Security software and application - Security Software & Appliance

TYPE: Security Software & Appliance

A vulnerability has been identified in GnuTLS. A remote user can cause denial of service conditions.

 

A remote user can send a specially crafted Elliptic Curve Cryptography (ECC) certificate or certificate signing request (CSR) that, when processed by the target application, will trigger a heap corruption error and cause the application to crash.

 

The error occurs when printing information (e.g., key ID) about the public key.


Impact

  • Denial of Service

System / Technologies affected

  • Versions prior to 3.1.28, 3.2.20, 3.3.10

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

  • The vendor has issued a fix (3.1.28, 3.2.20, 3.3.10).

Vulnerability Identifier


Source


Related Link