CVE Vulnerabilities

CVE-2013-4487

Published: Nov 20, 2013 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
6.8 MODERATE
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
MEDIUM

Off-by-one error in the dane_raw_tlsa in the DANE library (libdane) in GnuTLS 3.1.x before 3.1.16 and 3.2.x before 3.2.6 allows remote servers to cause a denial of service (memory corruption) via a response with more than four DANE entries. NOTE: this issue is due to an incomplete fix for CVE-2013-4466.

Affected Software

Name Vendor Start Version End Version
Gnutls Gnu 3.2.0 (including) 3.2.0 (including)
Gnutls Gnu 3.2.1 (including) 3.2.1 (including)
Gnutls Gnu 3.2.2 (including) 3.2.2 (including)
Gnutls Gnu 3.2.3 (including) 3.2.3 (including)
Gnutls Gnu 3.2.4 (including) 3.2.4 (including)
Gnutls Gnu 3.2.5 (including) 3.2.5 (including)
Gnutls28 Ubuntu saucy *
Gnutls28 Ubuntu upstream *

References