PT-2006-7556 · Gnu+1 · Gnutls+2

Evgeny Legerov

·

Published

1970-01-01

·

Updated

2018-10-19

·

CVE-2006-0645

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions GnuTLS versions 1.2.x through 1.2.9 GnuTLS versions 1.3.x through 1.3.3 Tiny ASN.1 Library (libtasn1) versions 0.2.17 and earlier
Description The issue allows attackers to crash the DER decoder and possibly execute arbitrary code via "out-of-bounds access" caused by invalid input. Exploitation of the vulnerabilities can lead to disruption of confidentiality, integrity, and availability of protected information and can be carried out remotely.
Recommendations For GnuTLS versions 1.2.x through 1.2.9, update to version 1.2.10 or later. For GnuTLS versions 1.3.x through 1.3.3, update to version 1.3.4 or later. For Tiny ASN.1 Library (libtasn1) versions 0.2.17 and earlier, update to version 0.2.18 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-02861
BDU:2015-02862
BDU:2015-02863
BDU:2015-09500
CVE-2006-0645
DSA-985-1
DSA-986-1
RHSA-2006:0207
RHSA-2006_0207

Affected Products

Gnutls
Red Hat
Tiny Asn.1 Library