PT-2011-1185 · Gnu+3 · Gnutls+3

Published

2011-12-08

·

Updated

2024-06-15

·

CVE-2011-4128

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions GnuTLS versions 2.12.x through 2.12.13 GnuTLS versions 3.x through 3.0.6
Description The issue is related to a buffer overflow in the gnutls session get data function, which can be triggered by remote TLS servers when used on a client that performs nonstandard session resumption, leading to a denial of service (application crash) via a large SessionTicket. Additionally, multiple vulnerabilities in the GnuTLS package can lead to breaches of confidentiality, integrity, and availability of protected information, and these vulnerabilities can be exploited remotely.
Recommendations For GnuTLS versions 2.12.x through 2.12.13, update to version 2.12.14 or later. For GnuTLS versions 3.x through 3.0.6, update to version 3.0.7 or later. As a temporary workaround, consider restricting the use of nonstandard session resumption to minimize the risk of exploitation.

Fix

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-09647
CESA-2012_0429
CVE-2011-4128
OPENSUSE-SU-2024:10105-1
RHSA-2012:0428
RHSA-2012:0429
RHSA-2012_0428
RHSA-2012_0429
SUSE-SU-2012_0120-1

Affected Products

Centos
Gnutls
Red Hat
Suse