Skip to main content

GnuTLS TLS Record Decoding Denial of Service Vulnerability

Last Update Date: 31 May 2013 16:47 Release Date: 31 May 2013 3933 Views

RISK: High Risk

TYPE: Security software and application - Security Software & Appliance

TYPE: Security Software & Appliance

A vulnerability has been identified in GnuTLS, which can be exploited by malicious people to cause a DoS (Denial of Service).  The vulnerability is caused due to an out-of-bounds read error within the "_gnutls_ciphertext2compressed()" function in lib/gnutls_cipher.c and can be exploited to cause a crash of the application using the library.


Impact

  • Denial of Service

System / Technologies affected

  • GnuTLS 2.x

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.


Vulnerability Identifier


Source


Related Link