Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Daiki Ueno

#20288of 53,633
12.7Total CVSS
Vulnerabilities · 2
Medium
2
PT-2023-8678
5.9
2023-10-23
Gnutls · Gnutls · CVE-2023-5981
**Name of the Vulnerable Software and Affected Versions** GnuTLS (affected versions not specified) **Description** A vulnerability was found related to the response times to malformed ciphertexts in RSA-PSK ClientKeyExchange, which differ from response times of ciphertexts with correct PKCS#1 v1.5 padding. This issue is associated with information disclosure through inconsistency. Exploitation of the vulnerability may allow a remote attacker to access confidential data. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2021-6619
6.8
2021-12-22
Gnutls · Gnutls · CVE-2021-4209
**Name of the Vulnerable Software and Affected Versions** GnuTLS (affected versions not specified) **Description** A NULL pointer dereference flaw was found in GnuTLS, related to the implementation of the `wrap nettle hash fast()` function in the cryptographic library. This flaw can cause undefined behavior when providing zero-length input to Nettle's hash update functions, which internally call `memcpy()`. The issue can lead to a denial of service after authentication in rare circumstances. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.