Lucene search

K
cve[email protected]CVE-2014-3466
HistoryJun 03, 2014 - 2:55 p.m.

CVE-2014-3466

2014-06-0314:55:10
CWE-119
web.nvd.nist.gov
72
cve-2014-3466
buffer overflow
gnutls
remote code execution
memory corruption
nvd

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

7.4 High

AI Score

Confidence

High

0.661 Medium

EPSS

Percentile

97.9%

Buffer overflow in the read_server_hello function in lib/gnutls_handshake.c in GnuTLS before 3.1.25, 3.2.x before 3.2.15, and 3.3.x before 3.3.4 allows remote servers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a long session id in a ServerHello message.

Affected configurations

NVD
Node
gnugnutlsMatch3.3.0-
OR
gnugnutlsMatch3.3.0pre0
OR
gnugnutlsMatch3.3.1
OR
gnugnutlsMatch3.3.2
OR
gnugnutlsMatch3.3.3
Node
gnugnutlsRange3.1.24
OR
gnugnutlsMatch3.1.0
OR
gnugnutlsMatch3.1.1
OR
gnugnutlsMatch3.1.2
OR
gnugnutlsMatch3.1.3
OR
gnugnutlsMatch3.1.4
OR
gnugnutlsMatch3.1.5
OR
gnugnutlsMatch3.1.6
OR
gnugnutlsMatch3.1.7
OR
gnugnutlsMatch3.1.8
OR
gnugnutlsMatch3.1.9
OR
gnugnutlsMatch3.1.10
OR
gnugnutlsMatch3.1.11
OR
gnugnutlsMatch3.1.12
OR
gnugnutlsMatch3.1.13
OR
gnugnutlsMatch3.1.14
OR
gnugnutlsMatch3.1.15
OR
gnugnutlsMatch3.1.16
OR
gnugnutlsMatch3.1.17
OR
gnugnutlsMatch3.1.18
OR
gnugnutlsMatch3.1.19
OR
gnugnutlsMatch3.1.20
OR
gnugnutlsMatch3.1.21
OR
gnugnutlsMatch3.1.22
OR
gnugnutlsMatch3.1.23
Node
gnugnutlsMatch3.2.0
OR
gnugnutlsMatch3.2.1
OR
gnugnutlsMatch3.2.2
OR
gnugnutlsMatch3.2.3
OR
gnugnutlsMatch3.2.4
OR
gnugnutlsMatch3.2.5
OR
gnugnutlsMatch3.2.6
OR
gnugnutlsMatch3.2.7
OR
gnugnutlsMatch3.2.8
OR
gnugnutlsMatch3.2.8.1
OR
gnugnutlsMatch3.2.9
OR
gnugnutlsMatch3.2.10
OR
gnugnutlsMatch3.2.11
OR
gnugnutlsMatch3.2.12
OR
gnugnutlsMatch3.2.12.1
OR
gnugnutlsMatch3.2.13
OR
gnugnutlsMatch3.2.14

References

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

7.4 High

AI Score

Confidence

High

0.661 Medium

EPSS

Percentile

97.9%