Description
gnutls_cipher.c in libgnutls in GnuTLS before 2.12.17 and 3.x before 3.0.15 does not properly handle data encrypted with a block cipher, which allows remote attackers to cause a denial of service (heap memory corruption and application crash) via a crafted record, as demonstrated by a crafted GenericBlockCipher structure.
CVSS vector
AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9Complexity: Low
Confidentiality: None
Integrity: None
Affected Packages1 packages
🔴Vulnerability Details
3GHSAGHSA-h34x-7v7j-22v5: gnutls_cipher↗2022-05-14 ▶ CVEListCVE-2012-1573: gnutls_cipher↗2012-03-26 ▶ OSVCVE-2012-1573: gnutls_cipher↗2012-03-26 ▶ 📋Vendor Advisories
3UbuntuGnuTLS vulnerabilities↗2012-04-05 ▶ Red Hatgnutls: TLS record handling issue (GNUTLS-SA-2012-2, MU-201202-01)↗2012-03-21 ▶ DebianCVE-2012-1573: gnutls28 - gnutls_cipher.c in libgnutls in GnuTLS before 2.12.17 and 3.x before 3.0.15 does...↗2012 ▶ 💬Community
3BugzillaCVE-2012-1573 gnutls: TLS record handling issue (GNUTLS-SA-2012-2, MU-201202-01)↗2012-03-21 ▶ BugzillaCVE-2012-1573 gnutls: TLS record handling issue [fedora-all]↗2012-03-21 ▶ BugzillaCVE-2012-1573 mingw32-gnutls: TLS record handling issue [fedora-all]↗2012-03-21 ▶