Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:26646
HistorySep 07, 2020 - 3:06 a.m.

Denial Of Service (DoS)

2020-09-0703:06:27
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
9

0.004 Low

EPSS

Percentile

73.2%

gnutls is vulnerable to denial of service (DoS). The vulnerability exists as a server can trigger a NULL pointer dereference in a TLS 1.3 client if a no_renegotiation alert is sent with unexpected timing, and then an invalid second handshake occurs. The issue occurs where the gnutls_deinit function is called after detecting a handshake failure.