CVE-2013-2116
published 2013-07-03CVE-2013-2116: The _gnutls_ciphertext2compressed function in lib/gnutls_cipher.c in GnuTLS 2.12.23 allows remote attackers to cause a denial of service (buffer over-read and…
PriorityP425medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
3.76%
88.8th percentile
The _gnutls_ciphertext2compressed function in lib/gnutls_cipher.c in GnuTLS 2.12.23 allows remote attackers to cause a denial of service (buffer over-read and crash) via a crafted padding length. NOTE: this might be due to an incorrect fix for CVE-2013-0169.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gnu | gnutls | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_redhat2.6LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
VMware vCenter Chargeback Manager Remote Code Execution
vendor_vmware·2013-06-11·CVSS 5.0
CVE-2013-0166 [MEDIUM] VMware vCenter Chargeback Manager Remote Code Execution
VMSA-2013-0008: VMware vCenter Chargeback Manager Remote Code Execution
a. vCenter Chargeback Manager Remote Code Execution The vCenter Chargeback Manager (CBM) contains a flaw in its handling of file uploads. Exploitation of this issue may allow an unauthenticated attacker to execute code remotely. VMware would like to thank Andrea Micalizzi, aka rgod, for reporting this issue to us through HP's Zero Day Initiative (ZDI). The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2013-3520 to this issue. Column 4 of the following table lists the action required to remediate the vulnerability in each release, if a solution is available. VMware Product Product Version Running on Replace with / Apply Patch VMware Product CBM Product Version 2.01 Running on an
Red Hat
gnutls: out of bounds read in _gnutls_ciphertext2compressed (GNUTLS-SA-2013-2)
vendor_redhat·2013-05-29·CVSS 2.6
CVE-2013-2116 [LOW] CWE-125 gnutls: out of bounds read in _gnutls_ciphertext2compressed (GNUTLS-SA-2013-2)
gnutls: out of bounds read in _gnutls_ciphertext2compressed (GNUTLS-SA-2013-2)
The _gnutls_ciphertext2compressed function in lib/gnutls_cipher.c in GnuTLS 2.12.23 allows remote attackers to cause a denial of service (buffer over-read and crash) via a crafted padding length. NOTE: this might be due to an incorrect fix for CVE-2013-0169.
Package: mingw32-gnutls (Red Hat Enterprise Linux 6) - Not affected
Ubuntu
GnuTLS vulnerability
vendor_ubuntu·2013-05-29
CVE-2013-2116 GnuTLS vulnerability
Title: GnuTLS vulnerability
Summary: GnuTLS could be made to crash if it received specially crafted network
traffic.
It was discovered that GnuTLS incorrectly handled certain padding bytes. A
remote attacker could use this flaw to cause an application using GnuTLS to
crash, leading to a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
GHSA
GHSA-2vj6-mvxm-4f5f: The _gnutls_ciphertext2compressed function in lib/gnutls_cipher
ghsa_unreviewed·2022-05-17·CVSS 2.6
CVE-2013-2116 [LOW] CWE-20 GHSA-2vj6-mvxm-4f5f: The _gnutls_ciphertext2compressed function in lib/gnutls_cipher
The _gnutls_ciphertext2compressed function in lib/gnutls_cipher.c in GnuTLS 2.12.23 allows remote attackers to cause a denial of service (buffer over-read and crash) via a crafted padding length. NOTE: this might be due to an incorrect fix for CVE-2013-0169.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-2116 mingw-gnutls: out of bounds read in _gnutls_ciphertext2compressed [fedora-all]
bugzilla·2013-05-29·CVSS 5.0
CVE-2013-2116 [MEDIUM] CVE-2013-2116 mingw-gnutls: out of bounds read in _gnutls_ciphertext2compressed [fedora-all]
CVE-2013-2116 mingw-gnutls: out of bounds read in _gnutls_ciphertext2compressed [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note:
Bugzilla
CVE-2013-2116 gnutls: out of bounds read in _gnutls_ciphertext2compressed [fedora-all]
bugzilla·2013-05-29·CVSS 5.0
CVE-2013-2116 [MEDIUM] CVE-2013-2116 gnutls: out of bounds read in _gnutls_ciphertext2compressed [fedora-all]
CVE-2013-2116 gnutls: out of bounds read in _gnutls_ciphertext2compressed [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this
Bugzilla
CVE-2013-2116 gnutls: out of bounds read in _gnutls_ciphertext2compressed (GNUTLS-SA-2013-2)
bugzilla·2013-05-23·CVSS 4.0
CVE-2013-2116 [MEDIUM] CVE-2013-2116 gnutls: out of bounds read in _gnutls_ciphertext2compressed (GNUTLS-SA-2013-2)
CVE-2013-2116 gnutls: out of bounds read in _gnutls_ciphertext2compressed (GNUTLS-SA-2013-2)
A flaw was found in the way GnuTLS decrypted TLS record packets when using CBC encryption. The number of pad bytes read form the packet was not checked against the cipher text size, resulting in an out of bounds read. This could cause a TLS client or server using GnuTLS to crash.
This problem was introduced by a fix for Lucky 13 issue CVE-2013-1619, released in Red Hat Enterprise Linux 5 and 6 via RHSA-2013:0588:
https://rhn.redhat.com/errata/RHSA-2013-0588.html
This issue did not affect GnuTLS 3.x which used different patch for Lucky 13, only patch for 2.x, which did not implement all protections to avoid leak of timing information, contains this bug.
Issue was reported on upstream mailing lis
http://lists.opensuse.org/opensuse-security-announce/2013-06/msg00019.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-03/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-03/msg00003.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0883.htmlhttp://secunia.com/advisories/53911http://secunia.com/advisories/57260http://secunia.com/advisories/57274http://thread.gmane.org/gmane.comp.encryption.gpg.gnutls.devel/6753http://thread.gmane.org/gmane.comp.encryption.gpg.gnutls.devel/6754http://www.debian.org/security/2013/dsa-2697http://www.gnutls.org/security.html#GNUTLS-SA-2013-2http://www.mandriva.com/security/advisories?name=MDVSA-2013:171http://www.securitytracker.com/id/1028603http://www.ubuntu.com/usn/USN-1843-1https://gitorious.org/gnutls/gnutls/commit/5164d5a1d57cd0372a5dd074382ca960ca18b27dhttp://lists.opensuse.org/opensuse-security-announce/2013-06/msg00019.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-03/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-03/msg00003.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0883.htmlhttp://secunia.com/advisories/53911http://secunia.com/advisories/57260http://secunia.com/advisories/57274http://thread.gmane.org/gmane.comp.encryption.gpg.gnutls.devel/6753http://thread.gmane.org/gmane.comp.encryption.gpg.gnutls.devel/6754http://www.debian.org/security/2013/dsa-2697http://www.gnutls.org/security.html#GNUTLS-SA-2013-2http://www.mandriva.com/security/advisories?name=MDVSA-2013:171http://www.securitytracker.com/id/1028603http://www.ubuntu.com/usn/USN-1843-1https://gitorious.org/gnutls/gnutls/commit/5164d5a1d57cd0372a5dd074382ca960ca18b27d
2013-07-03
Published