CVE-2010-0731
published 2010-03-26CVE-2010-0731: The gnutls_x509_crt_get_serial function in the GnuTLS library before 1.2.1, when running on big-endian, 64-bit platforms, calls the asn1_read_value with a…
PriorityP339high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
2.94%
85.6th percentile
The gnutls_x509_crt_get_serial function in the GnuTLS library before 1.2.1, when running on big-endian, 64-bit platforms, calls the asn1_read_value with a pointer to the wrong data type and the wrong length value, which allows remote attackers to bypass the certificate revocation list (CRL) check and cause a stack-based buffer overflow via a crafted X.509 certificate, related to extraction of a serial number.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gnu | gnutls | <= 1.2.0 | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
gnutls: gnutls_x509_crt_get_serial incorrect serial decoding from ASN1 (BE64) [GNUTLS-SA-2010-1]
vendor_redhat·2010-03-25·CVSS 7.5
CVE-2010-0731 [HIGH] gnutls: gnutls_x509_crt_get_serial incorrect serial decoding from ASN1 (BE64) [GNUTLS-SA-2010-1]
gnutls: gnutls_x509_crt_get_serial incorrect serial decoding from ASN1 (BE64) [GNUTLS-SA-2010-1]
The gnutls_x509_crt_get_serial function in the GnuTLS library before 1.2.1, when running on big-endian, 64-bit platforms, calls the asn1_read_value with a pointer to the wrong data type and the wrong length value, which allows remote attackers to bypass the certificate revocation list (CRL) check and cause a stack-based buffer overflow via a crafted X.509 certificate, related to extraction of a serial number.
GHSA
GHSA-g8xp-5hv7-77f4: The gnutls_x509_crt_get_serial function in the GnuTLS library before 1
ghsa_unreviewed·2022-05-02
CVE-2010-0731 [HIGH] CWE-119 GHSA-g8xp-5hv7-77f4: The gnutls_x509_crt_get_serial function in the GnuTLS library before 1
The gnutls_x509_crt_get_serial function in the GnuTLS library before 1.2.1, when running on big-endian, 64-bit platforms, calls the asn1_read_value with a pointer to the wrong data type and the wrong length value, which allows remote attackers to bypass the certificate revocation list (CRL) check and cause a stack-based buffer overflow via a crafted X.509 certificate, related to extraction of a serial number.
Suricata
GPL WEB_SERVER apache ?M=D directory list attempt
suricata·2010-09-23
CVE-2001-0731 GPL WEB_SERVER apache ?M=D directory list attempt
GPL WEB_SERVER apache ?M=D directory list attempt
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"GPL WEB_SERVER apache ?M=D directory list attempt"; flow:established,to_server; http.uri; content:"/?M=D"; reference:bugtraq,3009; reference:cve,2001-0731; classtype:web-application-activity; sid:2101519; rev:13; metadata:created_at 2010_09_23, cve CVE_2001_0731, signature_severity Unknown, updated_at 2024_03_08;)
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2010-08/msg00001.htmlhttp://secunia.com/advisories/39127http://thread.gmane.org/gmane.comp.encryption.gpg.gnutls.devel/4230http://www.mandriva.com/security/advisories?name=MDVSA-2010:089http://www.redhat.com/support/errata/RHSA-2010-0167.htmlhttp://www.securityfocus.com/bid/38959http://www.vupen.com/english/advisories/2010/0713http://www.vupen.com/english/advisories/2010/1054https://bugzilla.redhat.com/show_bug.cgi?id=573028https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9759http://lists.opensuse.org/opensuse-security-announce/2010-08/msg00001.htmlhttp://secunia.com/advisories/39127http://thread.gmane.org/gmane.comp.encryption.gpg.gnutls.devel/4230http://www.mandriva.com/security/advisories?name=MDVSA-2010:089http://www.redhat.com/support/errata/RHSA-2010-0167.htmlhttp://www.securityfocus.com/bid/38959http://www.vupen.com/english/advisories/2010/0713http://www.vupen.com/english/advisories/2010/1054https://bugzilla.redhat.com/show_bug.cgi?id=573028https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9759
2010-03-26
Published