Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:10814
HistoryJan 15, 2019 - 8:52 a.m.

Remote Code Execution (RCE)

2019-01-1508:52:35
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
8

0.661 Medium

EPSS

Percentile

97.9%

gnutls is vulnerable to remote code execution (RCE) attacks. The vulnerability exists due to a possible buffer overflow in the read_server_hello function in lib/gnutls_handshake.c in GnuTLS before 3.1.25, 3.2.x before 3.2.15, and 3.3.x before 3.3.4 allows remote servers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a long session id in a ServerHello message.

References