CVE-2014-3465
published 2014-06-10CVE-2014-3465: The gnutls_x509_dn_oid_name function in lib/x509/common.c in GnuTLS 3.0 before 3.1.20 and 3.2.x before 3.2.10 allows remote attackers to cause a denial of…
PriorityP428medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
6.78%
93.3th percentile
The gnutls_x509_dn_oid_name function in lib/x509/common.c in GnuTLS 3.0 before 3.1.20 and 3.2.x before 3.2.10 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted X.509 certificate, related to a missing LDAP description for an OID when printing the DN.
Affected
61 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | gnutls28 | < gnutls28 3.2.10-1 (bookworm) | gnutls28 3.2.10-1 (bookworm) |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-g8hv-44v8-257w: The gnutls_x509_dn_oid_name function in lib/x509/common
ghsa_unreviewed·2022-05-14
CVE-2014-3465 [MEDIUM] GHSA-g8hv-44v8-257w: The gnutls_x509_dn_oid_name function in lib/x509/common
The gnutls_x509_dn_oid_name function in lib/x509/common.c in GnuTLS 3.0 before 3.1.20 and 3.2.x before 3.2.10 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted X.509 certificate, related to a missing LDAP description for an OID when printing the DN.
OSV
CVE-2014-3465: The gnutls_x509_dn_oid_name function in lib/x509/common
osv·2014-06-10·CVSS 5.0
CVE-2014-3465 [MEDIUM] CVE-2014-3465: The gnutls_x509_dn_oid_name function in lib/x509/common
The gnutls_x509_dn_oid_name function in lib/x509/common.c in GnuTLS 3.0 before 3.1.20 and 3.2.x before 3.2.10 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted X.509 certificate, related to a missing LDAP description for an OID when printing the DN.
Red Hat
gnutls: gnutls_x509_dn_oid_name NULL pointer dereference
vendor_redhat·2014-01-31·CVSS 5.0
CVE-2014-3465 [MEDIUM] CWE-476 gnutls: gnutls_x509_dn_oid_name NULL pointer dereference
gnutls: gnutls_x509_dn_oid_name NULL pointer dereference
The gnutls_x509_dn_oid_name function in lib/x509/common.c in GnuTLS 3.0 before 3.1.20 and 3.2.x before 3.2.10 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted X.509 certificate, related to a missing LDAP description for an OID when printing the DN.
Statement: This issue did not affect the versions of gnutls as shipped with Red Hat Enterprise Linux 4, 5, and 6.
Package: gnutls (Red Hat Enterprise Linux 4) - Not affected
Package: gnutls (Red Hat Enterprise Linux 5) - Not affected
Package: gnutls (Red Hat Enterprise Linux 6) - Not affected
Package: mingw32-gnutls (Red Hat Enterprise Linux 6) - Not affected
Debian
CVE-2014-3465: gnutls28 - The gnutls_x509_dn_oid_name function in lib/x509/common.c in GnuTLS 3.0 before 3...
vendor_debian·2014·CVSS 5.0
CVE-2014-3465 [MEDIUM] CVE-2014-3465: gnutls28 - The gnutls_x509_dn_oid_name function in lib/x509/common.c in GnuTLS 3.0 before 3...
The gnutls_x509_dn_oid_name function in lib/x509/common.c in GnuTLS 3.0 before 3.1.20 and 3.2.x before 3.2.10 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted X.509 certificate, related to a missing LDAP description for an OID when printing the DN.
Scope: local
bookworm: resolved (fixed in 3.2.10-1)
bullseye: resolved (fixed in 3.2.10-1)
forky: resolved (fixed in 3.2.10-1)
sid: resolved (fixed in 3.2.10-1)
trixie: resolved (fixed in 3.2.10-1)
No detection rules found.
No public exploits indexed.
http://lists.gnutls.org/pipermail/gnutls-help/2014-January/003326.htmlhttp://lists.gnutls.org/pipermail/gnutls-help/2014-January/003327.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-06/msg00007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-06/msg00010.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0684.htmlhttp://secunia.com/advisories/59086https://bugzilla.redhat.com/show_bug.cgi?id=1101734https://www.gitorious.org/gnutls/gnutls/commit/d3648ebb04b650e6d20a2ec1fb839256b30b9fc6http://lists.gnutls.org/pipermail/gnutls-help/2014-January/003326.htmlhttp://lists.gnutls.org/pipermail/gnutls-help/2014-January/003327.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-06/msg00007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-06/msg00010.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0684.htmlhttp://secunia.com/advisories/59086https://bugzilla.redhat.com/show_bug.cgi?id=1101734https://www.gitorious.org/gnutls/gnutls/commit/d3648ebb04b650e6d20a2ec1fb839256b30b9fc6
2014-06-10
Published