PT-2015-1926 · Gnu+1 · Gnutls+1

Kurt Roeckx

·

Published

2015-08-12

·

Updated

2024-06-15

·

CVE-2015-6251

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions GnuTLS versions prior to 3.3.17 GnuTLS versions 3.4.x prior to 3.4.4
Description The issue is related to a double free vulnerability that can be exploited by remote attackers to cause a denial of service. This can be achieved by providing a long DistinguishedName (DN) entry in a certificate. The vulnerability is associated with an error in memory management, specifically a double free error, which can lead to a denial of service.
Recommendations For GnuTLS versions prior to 3.3.17, update to version 3.3.17 or later. For GnuTLS versions 3.4.x prior to 3.4.4, update to version 3.4.4 or later.

Fix

Double Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-11272
CVE-2015-6251
DSA-3334-1
MGASA-2015-0322
OPENSUSE-SU-2024:10105-1
SUSE-SU-2015:1518-1
USN-2727-1

Affected Products

Gnutls
Suse