PT-2017-17963 · Gnu+5 · Gnutls+5
Publicado
2017-03-07
·
Atualizado
2024-06-15
·
CVE-2017-7869
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
GnuTLS versions prior to 3.5.10
Description
The issue is caused by an integer overflow and heap-based buffer overflow related to the
cdk pkt read function in opencdk/read-packet.c. This is a subset of the vendor's report and has been fixed.Recommendations
For versions prior to 3.5.10, update to version 3.5.10 to resolve the issue. As a temporary workaround, consider restricting access to the
cdk pkt read function until the update is applied.Correção
Memory Corruption
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Centos
Gnutls
Red Hat
Suse
Ubuntu