CVE-2015-8313Observable Discrepancy in Gnutls

Severity
5.9MEDIUMNVD
EPSS
1.1%
top 22.29%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 20
Latest updateMay 24

Description

GnuTLS incorrectly validates the first byte of padding in CBC modes

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 2.2 | Impact: 3.6

Affected Packages1 packages

NVDgnu/gnutls2.0.02.12.24

Also affects: Debian Linux 10.0, 7.0, 8.0, 9.0

Patches

🔴Vulnerability Details

3
GHSA
GHSA-p72h-2892-8mjc: GnuTLS incorrectly validates the first byte of padding in CBC modes2022-05-24
CVEList
CVE-2015-8313: GnuTLS incorrectly validates the first byte of padding in CBC modes2019-12-20
OSV
CVE-2015-8313: GnuTLS incorrectly validates the first byte of padding in CBC modes2015-11-30

📋Vendor Advisories

2
Red Hat
gnutls: First byte of the padding in CBC mode is not checked2015-12-01
Debian
CVE-2015-8313: gnutls28 - GnuTLS incorrectly validates the first byte of padding in CBC modes2015

💬Community

1
Bugzilla
CVE-2015-8313 gnutls: First byte of the padding in CBC mode is not checked2015-12-02
CVE-2015-8313 — Observable Discrepancy in GNU Gnutls | cvebase