Gentoo · Gentoo Linux · CVE-2012-1573
**Name of the Vulnerable Software and Affected Versions**
GnuTLS versions prior to 3.0.15
GnuTLS versions prior to 2.12.18
**Description**
The issue affects the gnutls package in Gentoo Linux, potentially compromising the confidentiality, integrity, and availability of protected information. Exploitation can occur remotely. Specifically, `gnutls cipher.c` in `libgnutls` does not properly handle data encrypted with a block cipher, allowing remote attackers to cause a denial of service via a crafted record, such as a crafted `GenericBlockCipher` structure.
**Recommendations**
For versions prior to 2.12.18, update to version 2.12.18 or later.
For versions prior to 3.0.15, update to version 3.0.15 or later.
As a temporary workaround, consider restricting access to the `gnutls cipher.c` function in `libgnutls` until a patch is available.