PT-2013-1059 · Gnu+4 · Gnutls+4

CVE-2013-2116

·

Publicado

2013-05-30

·

Atualizado

2023-02-13

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions GnuTLS versions prior to 2.12.23
Description The issue is related to multiple vulnerabilities in the GnuTLS package, which can be exploited remotely to cause a denial of service, leading to disruption of protected information availability. Specifically, the gnutls ciphertext2compressed function in lib/gnutls cipher.c in GnuTLS 2.12.23 allows remote attackers to cause a denial of service via a crafted padding length.
Recommendations For versions prior to 2.12.23, update to version 2.12.23 or later to resolve the issue. As a temporary workaround, consider restricting access to the gnutls ciphertext2compressed function until a patch is available.

Correção

DoS

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2014-1263
BDU:2015-01328
BDU:2015-09730
CESA-2013_0883
CVE-2013-2116
DSA-2697-1
RHSA-2013:0883
RHSA-2013:1076
RHSA-2013_0883
SUSE-SU-2013_1060-1
SUSE-SU-2013_1060-2

Produtos afetados

Alt Linux
Centos
Gnutls
Red Hat
Suse