CVE-2015-6251
published 2015-08-24CVE-2015-6251: Double free vulnerability in GnuTLS before 3.3.17 and 3.4.x before 3.4.4 allows remote attackers to cause a denial of service via a long DistinguishedName (DN)…
PriorityP431medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
19.03%
97.0th percentile
Double free vulnerability in GnuTLS before 3.3.17 and 3.4.x before 3.4.4 allows remote attackers to cause a denial of service via a long DistinguishedName (DN) entry in a certificate.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | gnutls28 | < gnutls28 3.3.17-1 (bookworm) | gnutls28 3.3.17-1 (bookworm) |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_ubuntu7.5HIGH
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-63p6-5792-gpfq: Double free vulnerability in GnuTLS before 3
ghsa_unreviewed·2022-05-17
CVE-2015-6251 [MEDIUM] GHSA-63p6-5792-gpfq: Double free vulnerability in GnuTLS before 3
Double free vulnerability in GnuTLS before 3.3.17 and 3.4.x before 3.4.4 allows remote attackers to cause a denial of service via a long DistinguishedName (DN) entry in a certificate.
OSV
CVE-2015-6251: Double free vulnerability in GnuTLS before 3
osv·2015-08-24·CVSS 5.0
CVE-2015-6251 [MEDIUM] CVE-2015-6251: Double free vulnerability in GnuTLS before 3
Double free vulnerability in GnuTLS before 3.3.17 and 3.4.x before 3.4.4 allows remote attackers to cause a denial of service via a long DistinguishedName (DN) entry in a certificate.
Ubuntu
GnuTLS vulnerabilities
vendor_ubuntu·2015-09-01·CVSS 7.5
CVE-2015-3308 [HIGH] GnuTLS vulnerabilities
Title: GnuTLS vulnerabilities
Summary: GnuTLS could be made to crash or run programs if it processed a specially
crafted certificate.
It was discovered that GnuTLS incorrectly handled parsing CRL distribution
points. A remote attacker could possibly use this issue to cause a denial
of service, or execute arbitrary code. (CVE-2015-3308)
Kurt Roeckx discovered that GnuTLS incorrectly handled a long
DistinguishedName (DN) entry in a certificate. A remote attacker could
possibly use this issue to cause a denial of service, or execute arbitrary
code. (CVE-2015-6251)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
gnutls: double free flaw in certificate DN decoding (GNUTLS-SA-2015-3)
vendor_redhat·2015-08-10·CVSS 5.0
CVE-2015-6251 [MEDIUM] CWE-416 gnutls: double free flaw in certificate DN decoding (GNUTLS-SA-2015-3)
gnutls: double free flaw in certificate DN decoding (GNUTLS-SA-2015-3)
Double free vulnerability in GnuTLS before 3.3.17 and 3.4.x before 3.4.4 allows remote attackers to cause a denial of service via a long DistinguishedName (DN) entry in a certificate.
A use-after-free flaw was found in GnuTLS's _gnutls_x509_dn_to_string() function. A remote attacker could create a specially crafted certificate with very long DistinguishedName (DN) entries that, when processed by an application compiled against GnuTLS, could cause that application to crash.
Statement: This issue did not affect the versions of gnutls as shipped with Red Hat Enterprise Linux 4, 5, and 6.
Package: gnutls (Red Hat Enterprise Linux 5) - Not affected
Package: gnutls (Red Hat Enterprise Linux 6) - Not affected
Package: gn
Debian
CVE-2015-6251: gnutls28 - Double free vulnerability in GnuTLS before 3.3.17 and 3.4.x before 3.4.4 allows ...
vendor_debian·2015·CVSS 5.0
CVE-2015-6251 [MEDIUM] CVE-2015-6251: gnutls28 - Double free vulnerability in GnuTLS before 3.3.17 and 3.4.x before 3.4.4 allows ...
Double free vulnerability in GnuTLS before 3.3.17 and 3.4.x before 3.4.4 allows remote attackers to cause a denial of service via a long DistinguishedName (DN) entry in a certificate.
Scope: local
bookworm: resolved (fixed in 3.3.17-1)
bullseye: resolved (fixed in 3.3.17-1)
forky: resolved (fixed in 3.3.17-1)
sid: resolved (fixed in 3.3.17-1)
trixie: resolved (fixed in 3.3.17-1)
No detection rules found.
No public exploits indexed.
http://lists.fedoraproject.org/pipermail/package-announce/2015-September/165286.htmlhttp://lists.opensuse.org/opensuse-updates/2015-09/msg00001.htmlhttp://www.debian.org/security/2015/dsa-3334http://www.gnutls.org/security.html#GNUTLS-SA-2015-3http://www.openwall.com/lists/oss-security/2015/08/10/1http://www.openwall.com/lists/oss-security/2015/08/17/6http://www.securityfocus.com/bid/76267http://www.securitytracker.com/id/1033226https://bugzilla.redhat.com/show_bug.cgi?id=1251902https://gitlab.com/gnutls/gnutls/commit/272854367efc130fbd4f1a51840d80c630214e12http://lists.fedoraproject.org/pipermail/package-announce/2015-September/165286.htmlhttp://lists.opensuse.org/opensuse-updates/2015-09/msg00001.htmlhttp://www.debian.org/security/2015/dsa-3334http://www.gnutls.org/security.html#GNUTLS-SA-2015-3http://www.openwall.com/lists/oss-security/2015/08/10/1http://www.openwall.com/lists/oss-security/2015/08/17/6http://www.securityfocus.com/bid/76267http://www.securitytracker.com/id/1033226https://bugzilla.redhat.com/show_bug.cgi?id=1251902https://gitlab.com/gnutls/gnutls/commit/272854367efc130fbd4f1a51840d80c630214e12
2015-08-24
Published