PT-2013-5040 · Gnu · Gnutls

Tomas Hoger

·

Published

2013-11-19

·

Updated

2018-10-30

·

CVE-2013-4487

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions GnuTLS versions 3.1.x through 3.1.15 GnuTLS versions 3.2.x through 3.2.5
Description The issue is caused by an off-by-one error in the dane raw tlsa function of the DANE library (libdane) in GnuTLS. This error allows remote servers to cause a denial of service (memory corruption) by sending a response with more than four DANE entries.
Recommendations For GnuTLS versions 3.1.x through 3.1.15, update to version 3.1.16 or later. For GnuTLS versions 3.2.x through 3.2.5, update to version 3.2.6 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-4487

Affected Products

Gnutls