PT-2011-1185 · Gnu+3 · Gnutls+3
Published
2011-12-08
·
Updated
2024-06-15
·
CVE-2011-4128
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
GnuTLS versions 2.12.x through 2.12.13
GnuTLS versions 3.x through 3.0.6
Description
The issue is related to a buffer overflow in the
gnutls session get data function, which can be triggered by remote TLS servers when used on a client that performs nonstandard session resumption, leading to a denial of service (application crash) via a large SessionTicket. Additionally, multiple vulnerabilities in the GnuTLS package can lead to breaches of confidentiality, integrity, and availability of protected information, and these vulnerabilities can be exploited remotely.Recommendations
For GnuTLS versions 2.12.x through 2.12.13, update to version 2.12.14 or later.
For GnuTLS versions 3.x through 3.0.6, update to version 3.0.7 or later.
As a temporary workaround, consider restricting the use of nonstandard session resumption to minimize the risk of exploitation.
Fix
DoS
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Centos
Gnutls
Red Hat
Suse