PT-2017-2262 · Gnu+4 · Gnutls+4
Publicado
2017-01-11
·
Atualizado
2018-10-30
·
CVE-2017-5336
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
GnuTLS versions prior to 3.3.26
GnuTLS versions 3.5.x prior to 3.5.8
Description
The issue is related to a stack-based buffer overflow in the
cdk pk get keyid function, which can be exploited by remote attackers using a crafted OpenPGP certificate. This may allow attackers to have an unspecified impact on the system.Recommendations
For GnuTLS versions prior to 3.3.26, update to version 3.3.26 or later.
For GnuTLS versions 3.5.x prior to 3.5.8, update to version 3.5.8 or later.
As a temporary workaround, consider restricting the use of the
cdk pk get keyid function until a patch is available.Exploit
Correção
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Centos
Gnutls
Red Hat
Suse
Ubuntu