5 Medium
CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
PARTIAL
AV:N/AC:L/Au:N/C:N/I:N/A:P
0.003 Low
EPSS
Percentile
68.2%
Off-by-one error in the dane_raw_tlsa in the DANE library (libdane) in GnuTLS 3.1.x before 3.1.16 and 3.2.x before 3.2.6 allows remote servers to cause a denial of service (memory corruption) via a response with more than four DANE entries. NOTE: this issue is due to an incomplete fix for CVE-2013-4466.
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
Debian | 12 | all | gnutls28 | < 3.7.9-2+deb12u3 | gnutls28_3.7.9-2+deb12u3_all.deb |
Debian | 11 | all | gnutls28 | < 3.7.1-5+deb11u5 | gnutls28_3.7.1-5+deb11u5_all.deb |
Debian | 999 | all | gnutls28 | < 3.8.5-4 | gnutls28_3.8.5-4_all.deb |
Debian | 13 | all | gnutls28 | < 3.8.5-4 | gnutls28_3.8.5-4_all.deb |