CVE-2006-7239
published 2010-05-24CVE-2006-7239: The _gnutls_x509_oid2mac_algorithm function in lib/gnutls_algorithms.c in GnuTLS before 1.4.2 allows remote attackers to cause a denial of service (crash) via…
PriorityP419medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
1.54%
72.4th percentile
The _gnutls_x509_oid2mac_algorithm function in lib/gnutls_algorithms.c in GnuTLS before 1.4.2 allows remote attackers to cause a denial of service (crash) via a crafted X.509 certificate that uses a hash algorithm that is not supported by GnuTLS, which triggers a NULL pointer dereference.
Affected
42 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gnu | gnutls | <= 1.4.1 | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
GnuTLS vulnerability
vendor_ubuntu·2010-06-03
CVE-2006-7239 GnuTLS vulnerability
Title: GnuTLS vulnerability
Summary: Under certain circumstances, an attacker might be able to crash GnuTLS.
It was discovered that GnuTLS did not always properly verify the hash
algorithm of X.509 certificates. If an application linked against GnuTLS
processed a crafted certificate, an attacker could make GnuTLS dereference
a NULL pointer and cause a DoS via application crash.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
gnutls: unknown hash algorithm NULL pointer derefence [GNUTLS-SA-2006-2]
vendor_redhat·2006-08-12·CVSS 5.0
CVE-2006-7239 [MEDIUM] CWE-476 gnutls: unknown hash algorithm NULL pointer derefence [GNUTLS-SA-2006-2]
gnutls: unknown hash algorithm NULL pointer derefence [GNUTLS-SA-2006-2]
The _gnutls_x509_oid2mac_algorithm function in lib/gnutls_algorithms.c in GnuTLS before 1.4.2 allows remote attackers to cause a denial of service (crash) via a crafted X.509 certificate that uses a hash algorithm that is not supported by GnuTLS, which triggers a NULL pointer dereference.
Statement: This issue was addressed in Red Hat Enterprise Linux 5 via RHBA-2012:0319: https://rhn.redhat.com/errata/RHBA-2012-0319.html
It did not affect versions of gnutls as shipped with Red Hat Enterprise Linux 4 and 6.
Package: gnutls (Red Hat Enterprise Linux 4) - Not affected
Package: gnutls (Red Hat Enterprise Linux 6) - Not affected
GHSA
GHSA-p7rq-x368-qjpx: The _gnutls_x509_oid2mac_algorithm function in lib/gnutls_algorithms
ghsa_unreviewed·2022-05-01
CVE-2006-7239 [MEDIUM] GHSA-p7rq-x368-qjpx: The _gnutls_x509_oid2mac_algorithm function in lib/gnutls_algorithms
The _gnutls_x509_oid2mac_algorithm function in lib/gnutls_algorithms.c in GnuTLS before 1.4.2 allows remote attackers to cause a denial of service (crash) via a crafted X.509 certificate that uses a hash algorithm that is not supported by GnuTLS, which triggers a NULL pointer dereference.
No detection rules found.
No public exploits indexed.
http://lists.gnupg.org/pipermail/gnutls-dev/2006-August/001190.htmlhttp://lists.gnupg.org/pipermail/gnutls-dev/2006-August/001192.htmlhttp://www.gnu.org/software/gnutls/security.htmlhttp://lists.gnupg.org/pipermail/gnutls-dev/2006-August/001190.htmlhttp://lists.gnupg.org/pipermail/gnutls-dev/2006-August/001192.htmlhttp://www.gnu.org/software/gnutls/security.html
2010-05-24
Published