PT-2017-8493 · Gnu+1 · Gnutls+1

Adam Mariš

·

Published

2016-06-08

·

Updated

2020-06-16

·

CVE-2016-4456

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions gnutls version 3.4.12
Description The issue allows remote attackers to overwrite and corrupt arbitrary files in the filesystem due to the "GNUTLS KEYLOGFILE" environment variable.
Recommendations For gnutls version 3.4.12, consider restricting access to the GNUTLS KEYLOGFILE environment variable to prevent remote attackers from overwriting arbitrary files until a patch is available.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2016-1590
CVE-2016-4456

Affected Products

Alt Linux
Gnutls