Lucene search

K
nvd[email protected]NVD:CVE-2014-3465
HistoryJun 10, 2014 - 2:55 p.m.

CVE-2014-3465

2014-06-1014:55:10
web.nvd.nist.gov
1

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

6.3 Medium

AI Score

Confidence

Low

0.04 Low

EPSS

Percentile

92.1%

The gnutls_x509_dn_oid_name function in lib/x509/common.c in GnuTLS 3.0 before 3.1.20 and 3.2.x before 3.2.10 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted X.509 certificate, related to a missing LDAP description for an OID when printing the DN.

Affected configurations

NVD
Node
gnugnutlsMatch3.0.0
OR
gnugnutlsMatch3.0.1
OR
gnugnutlsMatch3.0.2
OR
gnugnutlsMatch3.0.3
OR
gnugnutlsMatch3.0.4
OR
gnugnutlsMatch3.0.5
OR
gnugnutlsMatch3.0.6
OR
gnugnutlsMatch3.0.7
OR
gnugnutlsMatch3.0.8
OR
gnugnutlsMatch3.0.9
OR
gnugnutlsMatch3.0.10
OR
gnugnutlsMatch3.0.11
OR
gnugnutlsMatch3.0.12
OR
gnugnutlsMatch3.0.13
OR
gnugnutlsMatch3.0.14
OR
gnugnutlsMatch3.0.15
OR
gnugnutlsMatch3.0.16
OR
gnugnutlsMatch3.0.17
OR
gnugnutlsMatch3.0.18
OR
gnugnutlsMatch3.0.19
OR
gnugnutlsMatch3.0.20
OR
gnugnutlsMatch3.0.21
OR
gnugnutlsMatch3.0.22
OR
gnugnutlsMatch3.0.23
OR
gnugnutlsMatch3.0.24
OR
gnugnutlsMatch3.0.25
OR
gnugnutlsMatch3.0.26
OR
gnugnutlsMatch3.0.27
OR
gnugnutlsMatch3.0.28
OR
gnugnutlsMatch3.1.0
OR
gnugnutlsMatch3.1.1
OR
gnugnutlsMatch3.1.2
OR
gnugnutlsMatch3.1.3
OR
gnugnutlsMatch3.1.4
OR
gnugnutlsMatch3.1.5
OR
gnugnutlsMatch3.1.6
OR
gnugnutlsMatch3.1.7
OR
gnugnutlsMatch3.1.8
OR
gnugnutlsMatch3.1.9
OR
gnugnutlsMatch3.1.10
OR
gnugnutlsMatch3.1.11
OR
gnugnutlsMatch3.1.12
OR
gnugnutlsMatch3.1.13
OR
gnugnutlsMatch3.1.14
OR
gnugnutlsMatch3.1.15
OR
gnugnutlsMatch3.1.16
OR
gnugnutlsMatch3.1.17
OR
gnugnutlsMatch3.1.18
OR
gnugnutlsMatch3.1.19
OR
gnugnutlsMatch3.2.0
OR
gnugnutlsMatch3.2.1
OR
gnugnutlsMatch3.2.2
OR
gnugnutlsMatch3.2.3
OR
gnugnutlsMatch3.2.4
OR
gnugnutlsMatch3.2.5
OR
gnugnutlsMatch3.2.6
OR
gnugnutlsMatch3.2.7
OR
gnugnutlsMatch3.2.8
OR
gnugnutlsMatch3.2.8.1
OR
gnugnutlsMatch3.2.9

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

6.3 Medium

AI Score

Confidence

Low

0.04 Low

EPSS

Percentile

92.1%