PT-2013-1059 · Gnu+4 · Gnutls+4

Published

2013-05-30

·

Updated

2023-02-13

·

CVE-2013-2116

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions GnuTLS versions prior to 2.12.23
Description The issue is related to multiple vulnerabilities in the GnuTLS package, which can be exploited remotely to cause a denial of service, leading to disruption of protected information availability. Specifically, the gnutls ciphertext2compressed function in lib/gnutls cipher.c in GnuTLS 2.12.23 allows remote attackers to cause a denial of service via a crafted padding length.
Recommendations For versions prior to 2.12.23, update to version 2.12.23 or later to resolve the issue. As a temporary workaround, consider restricting access to the gnutls ciphertext2compressed function until a patch is available.

Fix

DoS

RCE

Weakness Enumeration

Related Identifiers

ALT-PU-2014-1263
BDU:2015-01328
BDU:2015-09730
CESA-2013_0883
CVE-2013-2116
DSA-2697-1
RHSA-2013:0883
RHSA-2013:1076
RHSA-2013_0883
SUSE-SU-2013_1060-1
SUSE-SU-2013_1060-2

Affected Products

Alt Linux
Centos
Gnutls
Red Hat
Suse