CVE-2015-8313
published 2019-12-20CVE-2015-8313: GnuTLS incorrectly validates the first byte of padding in CBC modes
PriorityP430medium5.9CVSS 3.1
AVNACHPRNUINSUCHINAN
EPSS
1.69%
74.6th percentile
GnuTLS incorrectly validates the first byte of padding in CBC modes
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | gnutls28 | — | — |
| gnu | gnutls | 2.0.0 – 2.12.24 | — |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv5.9MEDIUM
vendor_debian5.9LOW
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-p72h-2892-8mjc: GnuTLS incorrectly validates the first byte of padding in CBC modes
ghsa_unreviewed·2022-05-24
CVE-2015-8313 [MEDIUM] CWE-203 GHSA-p72h-2892-8mjc: GnuTLS incorrectly validates the first byte of padding in CBC modes
GnuTLS incorrectly validates the first byte of padding in CBC modes
OSV
CVE-2015-8313: GnuTLS incorrectly validates the first byte of padding in CBC modes
osv·2015-11-30·CVSS 5.9
CVE-2015-8313 [MEDIUM] CVE-2015-8313: GnuTLS incorrectly validates the first byte of padding in CBC modes
GnuTLS incorrectly validates the first byte of padding in CBC modes
Red Hat
gnutls: First byte of the padding in CBC mode is not checked
vendor_redhat·2015-12-01·CVSS 5.9
CVE-2015-8313 [MEDIUM] gnutls: First byte of the padding in CBC mode is not checked
gnutls: First byte of the padding in CBC mode is not checked
GnuTLS incorrectly validates the first byte of padding in CBC modes
Package: gnutls (Red Hat Enterprise Linux 5) - Not affected
Package: gnutls (Red Hat Enterprise Linux 6) - Not affected
Package: gnutls (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2015-8313: gnutls28 - GnuTLS incorrectly validates the first byte of padding in CBC modes
vendor_debian·2015·CVSS 5.9
CVE-2015-8313 [MEDIUM] CVE-2015-8313: gnutls28 - GnuTLS incorrectly validates the first byte of padding in CBC modes
GnuTLS incorrectly validates the first byte of padding in CBC modes
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
No detection rules found.
No public exploits indexed.
http://www.debian.org/security/2015/dsa-3408http://www.securityfocus.com/archive/1/537012/100/0/threadedhttp://www.securityfocus.com/bid/78327https://blog.hboeck.de/archives/877-A-little-POODLE-left-in-GnuTLS-old-versions.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=CVE-2015-8313https://bugzilla.suse.com/show_bug.cgi?id=CVE-2015-8313https://security-tracker.debian.org/tracker/CVE-2015-8313http://www.debian.org/security/2015/dsa-3408http://www.securityfocus.com/archive/1/537012/100/0/threadedhttp://www.securityfocus.com/bid/78327https://blog.hboeck.de/archives/877-A-little-POODLE-left-in-GnuTLS-old-versions.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=CVE-2015-8313https://bugzilla.suse.com/show_bug.cgi?id=CVE-2015-8313https://security-tracker.debian.org/tracker/CVE-2015-8313
2019-12-20
Published