Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:46363
HistoryApr 11, 2024 - 2:00 a.m.

Denial Of Service (DoS)

2024-04-1102:00:44
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
7
gnutls vulnerability dos resource consumption certtool crash

5 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H

7.1 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

13.2%

gnutls is vulnerable to Denial of Service(DoS). The vulnerability is due to excessive resource consumption caused by the “certtool --verify-chain” command when verifying a specially crafted .pem bundle, leading to an application crash.

5 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H

7.1 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

13.2%