CVE-2013-4466
published 2013-11-20CVE-2013-4466: Buffer overflow in the dane_query_tlsa function in the DANE library (libdane) in GnuTLS 3.1.x before 3.1.15 and 3.2.x before 3.2.5 allows remote servers to…
PriorityP426medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
1.98%
78.4th percentile
Buffer overflow in the dane_query_tlsa function in the DANE library (libdane) in GnuTLS 3.1.x before 3.1.15 and 3.2.x before 3.2.5 allows remote servers to cause a denial of service (memory corruption) via a response with more than four DANE entries.
Affected
24 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | gnutls28 | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| opensuse | opensuse | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0LOW
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
gnutls: dane_query_tlsa() CVE-2013-4466 fix off-by-one
vendor_redhat·2013-10-29·CVSS 5.0
CVE-2013-4487 [MEDIUM] CWE-193 gnutls: dane_query_tlsa() CVE-2013-4466 fix off-by-one
gnutls: dane_query_tlsa() CVE-2013-4466 fix off-by-one
Off-by-one error in the dane_raw_tlsa in the DANE library (libdane) in GnuTLS 3.1.x before 3.1.16 and 3.2.x before 3.2.6 allows remote servers to cause a denial of service (memory corruption) via a response with more than four DANE entries. NOTE: this issue is due to an incomplete fix for CVE-2013-4466.
Statement: Not vulnerable. This issue did not affect the versions of gnutls as shipped with Red Hat Enterprise Linux 5 and 6 as they did not include support for DANE protocol.
Package: gnutls (Red Hat Enterprise Linux 5) - Not affected
Package: gnutls (Red Hat Enterprise Linux 6) - Not affected
Package: mingw32-gnutls (Red Hat Enterprise Linux 6) - Not affected
Package: gnutls (Red Hat Enterprise Linux 7) - Not affected
Red Hat
gnutls: dane_query_tlsa() buffer overflow (GNUTLS-SA-2013-3)
vendor_redhat·2013-10-23·CVSS 5.0
CVE-2013-4466 [MEDIUM] gnutls: dane_query_tlsa() buffer overflow (GNUTLS-SA-2013-3)
gnutls: dane_query_tlsa() buffer overflow (GNUTLS-SA-2013-3)
Buffer overflow in the dane_query_tlsa function in the DANE library (libdane) in GnuTLS 3.1.x before 3.1.15 and 3.2.x before 3.2.5 allows remote servers to cause a denial of service (memory corruption) via a response with more than four DANE entries.
Statement: Not vulnerable. This issue did not affect the versions of gnutls as shipped with Red Hat Enterprise Linux 5 and 6 as they did not include support for DANE protocol.
Package: gnutls (Red Hat Enterprise Linux 5) - Not affected
Package: gnutls (Red Hat Enterprise Linux 6) - Not affected
Package: mingw32-gnutls (Red Hat Enterprise Linux 6) - Not affected
Package: gnutls (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2013-4487: gnutls28 - Off-by-one error in the dane_raw_tlsa in the DANE library (libdane) in GnuTLS 3....
vendor_debian·2013·CVSS 5.0
CVE-2013-4487 [MEDIUM] CVE-2013-4487: gnutls28 - Off-by-one error in the dane_raw_tlsa in the DANE library (libdane) in GnuTLS 3....
Off-by-one error in the dane_raw_tlsa in the DANE library (libdane) in GnuTLS 3.1.x before 3.1.16 and 3.2.x before 3.2.6 allows remote servers to cause a denial of service (memory corruption) via a response with more than four DANE entries. NOTE: this issue is due to an incomplete fix for CVE-2013-4466.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
Debian
CVE-2013-4466: gnutls28 - Buffer overflow in the dane_query_tlsa function in the DANE library (libdane) in...
vendor_debian·2013·CVSS 5.0
CVE-2013-4466 [MEDIUM] CVE-2013-4466: gnutls28 - Buffer overflow in the dane_query_tlsa function in the DANE library (libdane) in...
Buffer overflow in the dane_query_tlsa function in the DANE library (libdane) in GnuTLS 3.1.x before 3.1.15 and 3.2.x before 3.2.5 allows remote servers to cause a denial of service (memory corruption) via a response with more than four DANE entries.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
GHSA
GHSA-7hp3-frg2-6v54: Buffer overflow in the dane_query_tlsa function in the DANE library (libdane) in GnuTLS 3
ghsa_unreviewed·2022-05-17
CVE-2013-4466 [MEDIUM] CWE-119 GHSA-7hp3-frg2-6v54: Buffer overflow in the dane_query_tlsa function in the DANE library (libdane) in GnuTLS 3
Buffer overflow in the dane_query_tlsa function in the DANE library (libdane) in GnuTLS 3.1.x before 3.1.15 and 3.2.x before 3.2.5 allows remote servers to cause a denial of service (memory corruption) via a response with more than four DANE entries.
GHSA
GHSA-h477-mjwp-rx3j: Off-by-one error in the dane_raw_tlsa in the DANE library (libdane) in GnuTLS 3
ghsa_unreviewed·2022-05-14·CVSS 5.0
CVE-2013-4487 [MEDIUM] GHSA-h477-mjwp-rx3j: Off-by-one error in the dane_raw_tlsa in the DANE library (libdane) in GnuTLS 3
Off-by-one error in the dane_raw_tlsa in the DANE library (libdane) in GnuTLS 3.1.x before 3.1.16 and 3.2.x before 3.2.6 allows remote servers to cause a denial of service (memory corruption) via a response with more than four DANE entries. NOTE: this issue is due to an incomplete fix for CVE-2013-4466.
OSV
CVE-2013-4466: Buffer overflow in the dane_query_tlsa function in the DANE library (libdane) in GnuTLS 3
osv·2013-11-20·CVSS 5.0
CVE-2013-4466 [MEDIUM] CVE-2013-4466: Buffer overflow in the dane_query_tlsa function in the DANE library (libdane) in GnuTLS 3
Buffer overflow in the dane_query_tlsa function in the DANE library (libdane) in GnuTLS 3.1.x before 3.1.15 and 3.2.x before 3.2.5 allows remote servers to cause a denial of service (memory corruption) via a response with more than four DANE entries.
OSV
CVE-2013-4487: Off-by-one error in the dane_raw_tlsa in the DANE library (libdane) in GnuTLS 3
osv·2013-11-20·CVSS 5.0
CVE-2013-4487 [MEDIUM] CVE-2013-4487: Off-by-one error in the dane_raw_tlsa in the DANE library (libdane) in GnuTLS 3
Off-by-one error in the dane_raw_tlsa in the DANE library (libdane) in GnuTLS 3.1.x before 3.1.16 and 3.2.x before 3.2.6 allows remote servers to cause a denial of service (memory corruption) via a response with more than four DANE entries. NOTE: this issue is due to an incomplete fix for CVE-2013-4466.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-4487 gnutls: dane_query_tlsa() CVE-2013-4466 fix off-by-one
bugzilla·2013-11-01·CVSS 5.0
CVE-2013-4487 [MEDIUM] CVE-2013-4487 gnutls: dane_query_tlsa() CVE-2013-4466 fix off-by-one
CVE-2013-4487 gnutls: dane_query_tlsa() CVE-2013-4466 fix off-by-one
GnuTLS upstream recently fixed a bug, which seems to have emerged due to the fix implemented in CVE-2013-4466.
Upstream recommends to update to GnuTLS 3.1.16 and 3.2.6.
References:
http://seclists.org/oss-sec/2013/q4/199
Commits:
https://gitorious.org/gnutls/gnutls/commit/0dd5529509e46b11d5c0f3f26f99294e0e5fa6dc
https://gitorious.org/gnutls/gnutls/commit/ad6a243b5ad219fda7511d4cbc1f73d77414db77
Discussion:
Created gnutls tracking bugs for this issue:
Affects: fedora-all [bug 1025638]
---
This CVE is for an incorrect fix for CVE-2013-4466 (see bug 1022913). It contained an off-by-one error, causing it to possibly write 5 entries to 4 slot arrays in dane_query_st / dane_query_t. Problem is already mentioned in bug
Bugzilla
CVE-2013-4466 gnutls: dane_query_tlsa() buffer overflow (GNUTLS-SA-2013-3)
bugzilla·2013-10-24·CVSS 5.0
CVE-2013-4466 [MEDIUM] CVE-2013-4466 gnutls: dane_query_tlsa() buffer overflow (GNUTLS-SA-2013-3)
CVE-2013-4466 gnutls: dane_query_tlsa() buffer overflow (GNUTLS-SA-2013-3)
Upstream GnuTLS versions 3.1.15 and 3.2.5 correct a buffer overflow in dane_query_tlsa() function used to parse DANE (DNS-based Authentication of Named Entities) DNS records. The function parses DNS server reply into dane_query_st / dane_query_t struct which can hold up to 4 entries, but the function failed to check this and allowed parsing more then 4 entries form the reply, resulting in buffer overflow.
An application using DANE protocol to verify certificates could crash or, possibly, execute arbitrary code when parsing a response from a malicious DNS server.
Announcements of 3.1.15 and 3.2.5 versions:
http://lists.gnutls.org/pipermail/gnutls-devel/2013-October/006511.html
http://lists.gnutls.org/pipermail/gnu
http://article.gmane.org/gmane.comp.encryption.gpg.gnutls.devel/7049http://article.gmane.org/gmane.comp.encryption.gpg.gnutls.devel/7050http://www.gnutls.org/security.html#GNUTLS-SA-2013-3http://www.openwall.com/lists/oss-security/2013/10/25/2http://article.gmane.org/gmane.comp.encryption.gpg.gnutls.devel/7049http://article.gmane.org/gmane.comp.encryption.gpg.gnutls.devel/7050http://www.gnutls.org/security.html#GNUTLS-SA-2013-3http://www.openwall.com/lists/oss-security/2013/10/25/2
2013-11-20
Published