CVE-2005-1431
published 2005-05-03CVE-2005-1431: The "record packet parsing" in GnuTLS 1.2 before 1.2.3 and 1.0 before 1.0.25 allows remote attackers to cause a denial of service, possibly related to padding…
PriorityP417medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
1.93%
77.9th percentile
The "record packet parsing" in GnuTLS 1.2 before 1.2.3 and 1.0 before 1.0.25 allows remote attackers to cause a denial of service, possibly related to padding bytes in gnutils_cipher.c.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
GNU TLS library vulnerability
vendor_ubuntu·2005-05-13
CVE-2005-1431 GNU TLS library vulnerability
Title: GNU TLS library vulnerability
Summary: GNU TLS library vulnerability
A Denial of Service vulnerability was discovered in the GNU TLS
library, which provides common cryptographic algorithms and is used by
many applications in Ubuntu. Due to a missing consistency check of the
padding length field, specially crafted ciphertext blocks caused an
out of bounds memory access which could crash the application. It was
not possible to exploit this to execute any attacker specified code.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
gnutls record packet parsing DoS [GNUTLS-SA-2005-1]
vendor_redhat·2005-04-28·CVSS 5.0
CVE-2005-1431 [MEDIUM] gnutls record packet parsing DoS [GNUTLS-SA-2005-1]
gnutls record packet parsing DoS [GNUTLS-SA-2005-1]
The "record packet parsing" in GnuTLS 1.2 before 1.2.3 and 1.0 before 1.0.25 allows remote attackers to cause a denial of service, possibly related to padding bytes in gnutils_cipher.c.
GHSA
GHSA-mcj4-5q8p-wx2v: The "record packet parsing" in GnuTLS 1
ghsa_unreviewed·2022-05-01
CVE-2005-1431 [MEDIUM] GHSA-mcj4-5q8p-wx2v: The "record packet parsing" in GnuTLS 1
The "record packet parsing" in GnuTLS 1.2 before 1.2.3 and 1.0 before 1.0.25 allows remote attackers to cause a denial of service, possibly related to padding bytes in gnutils_cipher.c.
No detection rules found.
No public exploits indexed.
http://lists.gnupg.org/pipermail/gnutls-dev/2005-April/000858.htmlhttp://secunia.com/advisories/15193http://securitytracker.com/id?1013861http://www.osvdb.org/16054http://www.redhat.com/support/errata/RHSA-2005-430.htmlhttp://www.securityfocus.com/bid/13477https://exchange.xforce.ibmcloud.com/vulnerabilities/20328https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9238http://lists.gnupg.org/pipermail/gnutls-dev/2005-April/000858.htmlhttp://secunia.com/advisories/15193http://securitytracker.com/id?1013861http://www.osvdb.org/16054http://www.redhat.com/support/errata/RHSA-2005-430.htmlhttp://www.securityfocus.com/bid/13477https://exchange.xforce.ibmcloud.com/vulnerabilities/20328https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9238
2005-05-03
Published