CVE Vulnerabilities

CVE-2013-4487

Published: Nov 20, 2013 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
6.8 MODERATE
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Off-by-one error in the dane_raw_tlsa in the DANE library (libdane) in GnuTLS 3.1.x before 3.1.16 and 3.2.x before 3.2.6 allows remote servers to cause a denial of service (memory corruption) via a response with more than four DANE entries. NOTE: this issue is due to an incomplete fix for CVE-2013-4466.

Affected Software

NameVendorStart VersionEnd Version
GnutlsGnu3.2.0 (including)3.2.0 (including)
GnutlsGnu3.2.1 (including)3.2.1 (including)
GnutlsGnu3.2.2 (including)3.2.2 (including)
GnutlsGnu3.2.3 (including)3.2.3 (including)
GnutlsGnu3.2.4 (including)3.2.4 (including)
GnutlsGnu3.2.5 (including)3.2.5 (including)
Gnutls28Ubuntusaucy*
Gnutls28Ubuntuupstream*

References