PT-2005-2428 · Gnu+1 · Gnutls+1

Published

2005-05-03

·

Updated

2017-10-11

·

CVE-2005-1431

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions: GnuTLS versions 1.0 through 1.0.24 GnuTLS versions 1.2 through 1.2.2
Description: The issue in the "record packet parsing" of GnuTLS allows remote attackers to cause a denial of service, possibly related to padding bytes in gnutils cipher.c.
Recommendations: For GnuTLS versions 1.0 through 1.0.24, update to version 1.0.25 or later. For GnuTLS versions 1.2 through 1.2.2, update to version 1.2.3 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-1431
RHSA-2005:430
RHSA-2005_430

Affected Products

Gnutls
Red Hat