A flaw was found in gnutls. A remote, unauthenticated attacker can exploit this vulnerability by sending a specially crafted ClientHello message with an invalid Pre-Shared Key (PSK) binder value during the TLS handshake. This can lead to a NULL pointer dereference, causing the server to crash and resulting in a remote Denial of Service (DoS) condition.
The product dereferences a pointer that it expects to be valid but is NULL.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Gnutls | Gnu | - (including) | - (including) |
| Hardened_images | Redhat | - (including) | - (including) |
| Red Hat Hardened Images | RedHat | gnutls-main-3.8.12-1.1.hum1 | * |
| Gnutls28 | Ubuntu | upstream | * |