PT-2006-7556 · Gnu+1 · Gnutls+2
Evgeny Legerov
·
Publicado
1970-01-01
·
Atualizado
2018-10-19
·
CVE-2006-0645
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
GnuTLS versions 1.2.x through 1.2.9
GnuTLS versions 1.3.x through 1.3.3
Tiny ASN.1 Library (libtasn1) versions 0.2.17 and earlier
Description
The issue allows attackers to crash the DER decoder and possibly execute arbitrary code via "out-of-bounds access" caused by invalid input. Exploitation of the vulnerabilities can lead to disruption of confidentiality, integrity, and availability of protected information and can be carried out remotely.
Recommendations
For GnuTLS versions 1.2.x through 1.2.9, update to version 1.2.10 or later.
For GnuTLS versions 1.3.x through 1.3.3, update to version 1.3.4 or later.
For Tiny ASN.1 Library (libtasn1) versions 0.2.17 and earlier, update to version 0.2.18 or later.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Gnutls
Red Hat
Tiny Asn.1 Library