GnuTLS TLS Record Decoding Denial of Service Vulnerability
Last Update Date:
31 May 2013 16:47
Release Date:
31 May 2013
3933
Views
RISK: High Risk
TYPE: Security software and application - Security Software & Appliance
A vulnerability has been identified in GnuTLS, which can be exploited by malicious people to cause a DoS (Denial of Service). The vulnerability is caused due to an out-of-bounds read error within the "_gnutls_ciphertext2compressed()" function in lib/gnutls_cipher.c and can be exploited to cause a crash of the application using the library.
Impact
- Denial of Service
System / Technologies affected
- GnuTLS 2.x
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Fixed in the git repository.
http://www.gnutls.org/security.html#GNUTLS-SA-2013-2
Vulnerability Identifier
Source
Related Link
Share with