CVE-2009-1415
published 2009-04-30CVE-2009-1415: lib/pk-libgcrypt.c in libgnutls in GnuTLS before 2.6.6 does not properly handle invalid DSA signatures, which allows remote attackers to cause a denial of…
PriorityP423medium4.3CVSS 2.0
AVNACMAuNCNINAP
EXPLOIT
EPSS
7.92%
94.1th percentile
lib/pk-libgcrypt.c in libgnutls in GnuTLS before 2.6.6 does not properly handle invalid DSA signatures, which allows remote attackers to cause a denial of service (application crash) and possibly have unspecified other impact via a malformed DSA key that triggers a (1) free of an uninitialized pointer or (2) double free.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gnu | gnutls | < 2.6.6 | 2.6.6 |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
vendor_redhat4.3MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2vg6-3mr6-w5mp: lib/pk-libgcrypt
ghsa_unreviewed·2022-05-02
CVE-2009-1415 [MEDIUM] CWE-824 GHSA-2vg6-3mr6-w5mp: lib/pk-libgcrypt
lib/pk-libgcrypt.c in libgnutls in GnuTLS before 2.6.6 does not properly handle invalid DSA signatures, which allows remote attackers to cause a denial of service (application crash) and possibly have unspecified other impact via a malformed DSA key that triggers a (1) free of an uninitialized pointer or (2) double free.
Red Hat
gnutls: Double free and free of invalid pointer on certain errors [GNUTLS-SA-2009-1]
vendor_redhat·2009-04-30·CVSS 4.3
CVE-2009-1415 [MEDIUM] gnutls: Double free and free of invalid pointer on certain errors [GNUTLS-SA-2009-1]
gnutls: Double free and free of invalid pointer on certain errors [GNUTLS-SA-2009-1]
lib/pk-libgcrypt.c in libgnutls in GnuTLS before 2.6.6 does not properly handle invalid DSA signatures, which allows remote attackers to cause a denial of service (application crash) and possibly have unspecified other impact via a malformed DSA key that triggers a (1) free of an uninitialized pointer or (2) double free.
Statement: Not vulnerable. This issue did not affect versions of gnutls shipped in Red Hat Enterprise Linux 4 and 5 as it only affected gnutls 2.6.x versions.
No detection rules found.
http://article.gmane.org/gmane.comp.encryption.gpg.gnutls.devel/3515http://permalink.gmane.org/gmane.comp.encryption.gpg.gnutls.devel/3502http://secunia.com/advisories/34842http://secunia.com/advisories/35211http://security.gentoo.org/glsa/glsa-200905-04.xmlhttp://thread.gmane.org/gmane.comp.encryption.gpg.gnutls.devel/3488http://www.mandriva.com/security/advisories?name=MDVSA-2009:116http://www.securityfocus.com/bid/34783http://www.securitytracker.com/id?1022157http://www.vupen.com/english/advisories/2009/1218https://exchange.xforce.ibmcloud.com/vulnerabilities/50257https://exchange.xforce.ibmcloud.com/vulnerabilities/50260https://exchange.xforce.ibmcloud.com/vulnerabilities/50445http://article.gmane.org/gmane.comp.encryption.gpg.gnutls.devel/3515http://permalink.gmane.org/gmane.comp.encryption.gpg.gnutls.devel/3502http://secunia.com/advisories/34842http://secunia.com/advisories/35211http://security.gentoo.org/glsa/glsa-200905-04.xmlhttp://thread.gmane.org/gmane.comp.encryption.gpg.gnutls.devel/3488http://www.mandriva.com/security/advisories?name=MDVSA-2009:116http://www.securityfocus.com/bid/34783http://www.securitytracker.com/id?1022157http://www.vupen.com/english/advisories/2009/1218https://exchange.xforce.ibmcloud.com/vulnerabilities/50257https://exchange.xforce.ibmcloud.com/vulnerabilities/50260https://exchange.xforce.ibmcloud.com/vulnerabilities/50445
2009-04-30
Published