Lucene search

K
freebsdFreeBSDAECEE357-739E-11E1-A883-001CC0A36E12
HistoryMar 20, 2012 - 12:00 a.m.

gnutls -- possible overflow/Denial of service vulnerabilities

2012-03-2000:00:00
vuxml.freebsd.org
13

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

0.956 High

EPSS

Percentile

99.4%

Mu Dynamics, Inc. reports:

The block cipher decryption logic in GnuTLS assumed that a
record containing any data which was a multiple of the block
size was valid for further decryption processing, leading to
a heap corruption vulnerability.

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchgnutls< 2.12.18UNKNOWN
FreeBSDanynoarchgnutls-devel< 3.0.15UNKNOWN

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

0.956 High

EPSS

Percentile

99.4%