Lucene search

K
prionPRIOn knowledge basePRION:CVE-2016-7444
HistorySep 27, 2016 - 3:59 p.m.

Design/Logic Flaw

2016-09-2715:59:00
PRIOn knowledge base
www.prio-n.com
9

7 High

AI Score

Confidence

Low

0.006 Low

EPSS

Percentile

78.9%

The gnutls_ocsp_resp_check_crt function in lib/x509/ocsp.c in GnuTLS before 3.4.15 and 3.5.x before 3.5.4 does not verify the serial length of an OCSP response, which might allow remote attackers to bypass an intended certificate validation mechanism via vectors involving trailing bytes left by gnutls_malloc.