CVE-2014-3466
published 2014-06-03CVE-2014-3466: Buffer overflow in the read_server_hello function in lib/gnutls_handshake.c in GnuTLS before 3.1.25, 3.2.x before 3.2.15, and 3.3.x before 3.3.4 allows remote…
PriorityP341medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
11.22%
95.5th percentile
Buffer overflow in the read_server_hello function in lib/gnutls_handshake.c in GnuTLS before 3.1.25, 3.2.x before 3.2.15, and 3.3.x before 3.3.4 allows remote servers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a long session id in a ServerHello message.
Affected
47 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | gnutls28 | < gnutls28 3.2.15-1 (bookworm) | gnutls28 3.2.15-1 (bookworm) |
| gnu | gnutls | <= 3.1.24 | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
GnuTLS vulnerability
vendor_ubuntu·2014-06-02
CVE-2014-3466 GnuTLS vulnerability
Title: GnuTLS vulnerability
Summary: GnuTLS could be made to crash or run programs if it connected to a
malicious server.
Joonas Kuorilehto discovered that GnuTLS incorrectly handled Server Hello
messages. A malicious remote server or a machine-in-the-middle could use this
issue to cause GnuTLS to crash, resulting in a denial of service, or
possibly execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
gnutls: insufficient session id length check in _gnutls_read_server_hello (GNUTLS-SA-2014-3)
vendor_redhat·2014-05-30·CVSS 6.8
CVE-2014-3466 [MEDIUM] CWE-130 gnutls: insufficient session id length check in _gnutls_read_server_hello (GNUTLS-SA-2014-3)
gnutls: insufficient session id length check in _gnutls_read_server_hello (GNUTLS-SA-2014-3)
Buffer overflow in the read_server_hello function in lib/gnutls_handshake.c in GnuTLS before 3.1.25, 3.2.x before 3.2.15, and 3.3.x before 3.3.4 allows remote servers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a long session id in a ServerHello message.
A flaw was found in the way GnuTLS parsed session IDs from ServerHello messages of the TLS/SSL handshake. A malicious server could use this flaw to send an excessively long session ID value, which would trigger a buffer overflow in a connecting TLS/SSL client application using GnuTLS, causing the client application to crash or, possibly, execute arbitrary code.
Package: gnutls (Red Hat Enterprise Linux
Debian
CVE-2014-3466: gnutls28 - Buffer overflow in the read_server_hello function in lib/gnutls_handshake.c in G...
vendor_debian·2014·CVSS 6.8
CVE-2014-3466 [MEDIUM] CVE-2014-3466: gnutls28 - Buffer overflow in the read_server_hello function in lib/gnutls_handshake.c in G...
Buffer overflow in the read_server_hello function in lib/gnutls_handshake.c in GnuTLS before 3.1.25, 3.2.x before 3.2.15, and 3.3.x before 3.3.4 allows remote servers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a long session id in a ServerHello message.
Scope: local
bookworm: resolved (fixed in 3.2.15-1)
bullseye: resolved (fixed in 3.2.15-1)
forky: resolved (fixed in 3.2.15-1)
sid: resolved (fixed in 3.2.15-1)
trixie: resolved (fixed in 3.2.15-1)
GHSA
GHSA-cc2g-hj2r-x228: Buffer overflow in the read_server_hello function in lib/gnutls_handshake
ghsa_unreviewed·2022-05-14
CVE-2014-3466 [MEDIUM] CWE-119 GHSA-cc2g-hj2r-x228: Buffer overflow in the read_server_hello function in lib/gnutls_handshake
Buffer overflow in the read_server_hello function in lib/gnutls_handshake.c in GnuTLS before 3.1.25, 3.2.x before 3.2.15, and 3.3.x before 3.3.4 allows remote servers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a long session id in a ServerHello message.
OSV
CVE-2014-3466: Buffer overflow in the read_server_hello function in lib/gnutls_handshake
osv·2014-06-03·CVSS 6.8
CVE-2014-3466 [MEDIUM] CVE-2014-3466: Buffer overflow in the read_server_hello function in lib/gnutls_handshake
Buffer overflow in the read_server_hello function in lib/gnutls_handshake.c in GnuTLS before 3.1.25, 3.2.x before 3.2.15, and 3.3.x before 3.3.4 allows remote servers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a long session id in a ServerHello message.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-3466 gnutls: insufficient session id length check in _gnutls_read_server_hello (GNUTLS-SA-2014-3) [fedora-all]
bugzilla·2014-05-30·CVSS 6.8
CVE-2014-3466 [MEDIUM] CVE-2014-3466 gnutls: insufficient session id length check in _gnutls_read_server_hello (GNUTLS-SA-2014-3) [fedora-all]
CVE-2014-3466 gnutls: insufficient session id length check in _gnutls_read_server_hello (GNUTLS-SA-2014-3) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when avai
Bugzilla
CVE-2014-3466 mingw-gnutls: gnutls: insufficient session id length check in _gnutls_read_server_hello (GNUTLS-SA-2014-3) [fedora-all]
bugzilla·2014-05-30·CVSS 6.8
CVE-2014-3466 [MEDIUM] CVE-2014-3466 mingw-gnutls: gnutls: insufficient session id length check in _gnutls_read_server_hello (GNUTLS-SA-2014-3) [fedora-all]
CVE-2014-3466 mingw-gnutls: gnutls: insufficient session id length check in _gnutls_read_server_hello (GNUTLS-SA-2014-3) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes f
Bugzilla
CVE-2014-3466 mingw32-gnutls: gnutls: insufficient session id length check in _gnutls_read_server_hello (GNUTLS-SA-2014-3) [epel-5]
bugzilla·2014-05-30·CVSS 6.8
CVE-2014-3466 [MEDIUM] CVE-2014-3466 mingw32-gnutls: gnutls: insufficient session id length check in _gnutls_read_server_hello (GNUTLS-SA-2014-3) [epel-5]
CVE-2014-3466 mingw32-gnutls: gnutls: insufficient session id length check in _gnutls_read_server_hello (GNUTLS-SA-2014-3) [epel-5]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi note
Bugzilla
CVE-2014-3466 gnutls: insufficient session id length check in _gnutls_read_server_hello (GNUTLS-SA-2014-3)
bugzilla·2014-05-28·CVSS 6.8
CVE-2014-3466 [MEDIUM] CVE-2014-3466 gnutls: insufficient session id length check in _gnutls_read_server_hello (GNUTLS-SA-2014-3)
CVE-2014-3466 gnutls: insufficient session id length check in _gnutls_read_server_hello (GNUTLS-SA-2014-3)
A flaw was found in the way GnuTLS parsed session ids from Server Hello packets of the TLS/SSL handshake. A malicious server could use this flaw to send an excessively long session id value and trigger a buffer overflow in a connecting TLS/SSL client using GnuTLS, causing it to crash or, possibly, execute arbitrary code.
The flaw is in read_server_hello() / _gnutls_read_server_hello(), where session_id_len is checked to not exceed incoming packet size, but not checked to ensure it does not exceed maximum session id length:
https://www.gitorious.org/gnutls/gnutls/source/8d7d6c6:lib/gnutls_handshake.c#L1747
Discussion:
Created attachment 899870
Patch from Nikos Mavrogiannopoulos
--
http://linux.oracle.com/errata/ELSA-2014-0594.htmlhttp://linux.oracle.com/errata/ELSA-2014-0595.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-06/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-06/msg00007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-06/msg00010.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-06/msg00015.htmlhttp://radare.today/technical-analysis-of-the-gnutls-hello-vulnerability/http://rhn.redhat.com/errata/RHSA-2014-0594.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0595.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0684.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0815.htmlhttp://secunia.com/advisories/58340http://secunia.com/advisories/58598http://secunia.com/advisories/58601http://secunia.com/advisories/58642http://secunia.com/advisories/59016http://secunia.com/advisories/59021http://secunia.com/advisories/59057http://secunia.com/advisories/59086http://secunia.com/advisories/59408http://secunia.com/advisories/59838http://secunia.com/advisories/60384http://www-01.ibm.com/support/docview.wss?uid=swg21678776http://www-947.ibm.com/support/entry/portal/docdisplay?lndocid=MIGR-5096155http://www.debian.org/security/2014/dsa-2944http://www.gnutls.org/security.htmlhttp://www.novell.com/support/kb/doc.php?id=7015302http://www.novell.com/support/kb/doc.php?id=7015303http://www.securityfocus.com/bid/67741http://www.securitytracker.com/id/1030314http://www.ubuntu.com/usn/USN-2229-1https://bugzilla.redhat.com/show_bug.cgi?id=1101932https://www.gitorious.org/gnutls/gnutls/commit/688ea6428a432c39203d00acd1af0e7684e5ddfdhttp://linux.oracle.com/errata/ELSA-2014-0594.htmlhttp://linux.oracle.com/errata/ELSA-2014-0595.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-06/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-06/msg00007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-06/msg00010.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-06/msg00015.htmlhttp://radare.today/technical-analysis-of-the-gnutls-hello-vulnerability/http://rhn.redhat.com/errata/RHSA-2014-0594.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0595.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0684.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0815.htmlhttp://secunia.com/advisories/58340http://secunia.com/advisories/58598http://secunia.com/advisories/58601http://secunia.com/advisories/58642http://secunia.com/advisories/59016http://secunia.com/advisories/59021http://secunia.com/advisories/59057http://secunia.com/advisories/59086http://secunia.com/advisories/59408http://secunia.com/advisories/59838http://secunia.com/advisories/60384http://www-01.ibm.com/support/docview.wss?uid=swg21678776http://www-947.ibm.com/support/entry/portal/docdisplay?lndocid=MIGR-5096155http://www.debian.org/security/2014/dsa-2944http://www.gnutls.org/security.htmlhttp://www.novell.com/support/kb/doc.php?id=7015302http://www.novell.com/support/kb/doc.php?id=7015303http://www.securityfocus.com/bid/67741http://www.securitytracker.com/id/1030314http://www.ubuntu.com/usn/USN-2229-1https://bugzilla.redhat.com/show_bug.cgi?id=1101932https://www.gitorious.org/gnutls/gnutls/commit/688ea6428a432c39203d00acd1af0e7684e5ddfd
2014-06-03
Published