Lucene search

K
f5F5F5:K59836191
HistoryFeb 10, 2017 - 12:00 a.m.

K59836191 : GnuTLS vulnerabilities CVE-2017-5335, CVE-2017-5336, and CVE-2017-5337

2017-02-1000:00:00
my.f5.com
25

9.5 High

AI Score

Confidence

High

0.032 Low

EPSS

Percentile

91.2%

Security Advisory Description

The stream reading functions in lib/opencdk/read-packet.c in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allow remote attackers to cause a denial of service (out-of-memory error and crash) via a crafted OpenPGP certificate.

Stack-based buffer overflow in the cdk_pk_get_keyid function in lib/opencdk/pubkey.c in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allows remote attackers to have unspecified impact via a crafted OpenPGP certificate.

Multiple heap-based buffer overflows in the read_attribute function in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allow remote attackers to have unspecified impact via a crafted OpenPGP certificate.
Impact
An attacker may be able to exploit these vulnerabilities to execute arbitrary code. Failed exploit attempts may result in denial-of-service (DoS) conditions.