CVE-2016-7444
published 2016-09-27CVE-2016-7444: The gnutls_ocsp_resp_check_crt function in lib/x509/ocsp.c in GnuTLS before 3.4.15 and 3.5.x before 3.5.4 does not verify the serial length of an OCSP…
PriorityP342high7.5CVSS 3.0
AVNACLPRNUINSUCNIHAN
EPSS
2.44%
82.5th percentile
The gnutls_ocsp_resp_check_crt function in lib/x509/ocsp.c in GnuTLS before 3.4.15 and 3.5.x before 3.5.4 does not verify the serial length of an OCSP response, which might allow remote attackers to bypass an intended certificate validation mechanism via vectors involving trailing bytes left by gnutls_malloc.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | gnutls28 | < gnutls28 3.5.3-4 (bookworm) | gnutls28 3.5.3-4 (bookworm) |
| gnu | gnutls | <= 3.4.14 | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
GnuTLS vulnerability
vendor_ubuntu·2017-03-20·CVSS 7.5
CVE-2016-8610 [HIGH] GnuTLS vulnerability
Title: GnuTLS vulnerability
Summary: GnuTLS could be made to hang if it received specially crafted network
traffic.
USN-3183-1 fixed CVE-2016-8610 in GnuTLS in Ubuntu 16.04 LTS and Ubuntu
16.10. This update provides the corresponding update for Ubuntu 12.04 LTS
and Ubuntu 14.04 LTS.
Original advisory details:
Stefan Buehler discovered that GnuTLS incorrectly verified the serial
length of OCSP responses. A remote attacker could possibly use this issue
to bypass certain certificate validation measures. This issue only applied
to Ubuntu 16.04 LTS. (CVE-2016-7444)
Shi Lei discovered that GnuTLS incorrectly handled certain warning alerts.
A remote attacker could possibly use this issue to cause GnuTLS to hang,
resulting in a denial of service. This issue has only been addressed in
Ubuntu 1
Ubuntu
GnuTLS vulnerabilities
vendor_ubuntu·2017-02-01·CVSS 7.5
CVE-2016-7444 [HIGH] GnuTLS vulnerabilities
Title: GnuTLS vulnerabilities
Summary: Several security issues were fixed in GnuTLS.
Stefan Buehler discovered that GnuTLS incorrectly verified the serial
length of OCSP responses. A remote attacker could possibly use this issue
to bypass certain certificate validation measures. This issue only applied
to Ubuntu 16.04 LTS. (CVE-2016-7444)
Shi Lei discovered that GnuTLS incorrectly handled certain warning alerts.
A remote attacker could possibly use this issue to cause GnuTLS to hang,
resulting in a denial of service. This issue has only been addressed in
Ubuntu 16.04 LTS and Ubuntu 16.10. (CVE-2016-8610)
It was discovered that GnuTLS incorrectly decoded X.509 certificates with a
Proxy Certificate Information extension. A remote attacker could use this
issue to cause GnuTLS to crash, re
Red Hat
gnutls: Incorrect certificate validation when using OCSP responses (GNUTLS-SA-2016-3)
vendor_redhat·2016-09-02·CVSS 7.5
CVE-2016-7444 [HIGH] CWE-295 gnutls: Incorrect certificate validation when using OCSP responses (GNUTLS-SA-2016-3)
gnutls: Incorrect certificate validation when using OCSP responses (GNUTLS-SA-2016-3)
The gnutls_ocsp_resp_check_crt function in lib/x509/ocsp.c in GnuTLS before 3.4.15 and 3.5.x before 3.5.4 does not verify the serial length of an OCSP response, which might allow remote attackers to bypass an intended certificate validation mechanism via vectors involving trailing bytes left by gnutls_malloc.
A flaw was found in the way GnuTLS validated certificates using OCSP responses. This could falsely report a certificate as valid under certain circumstances.
Package: gnutls (Red Hat Enterprise Linux 5) - Not affected
Package: gnutls (Red Hat Enterprise Linux 6) - Not affected
Debian
CVE-2016-7444: gnutls28 - The gnutls_ocsp_resp_check_crt function in lib/x509/ocsp.c in GnuTLS before 3.4....
vendor_debian·2016·CVSS 7.5
CVE-2016-7444 [HIGH] CVE-2016-7444: gnutls28 - The gnutls_ocsp_resp_check_crt function in lib/x509/ocsp.c in GnuTLS before 3.4....
The gnutls_ocsp_resp_check_crt function in lib/x509/ocsp.c in GnuTLS before 3.4.15 and 3.5.x before 3.5.4 does not verify the serial length of an OCSP response, which might allow remote attackers to bypass an intended certificate validation mechanism via vectors involving trailing bytes left by gnutls_malloc.
Scope: local
bookworm: resolved (fixed in 3.5.3-4)
bullseye: resolved (fixed in 3.5.3-4)
forky: resolved (fixed in 3.5.3-4)
sid: resolved (fixed in 3.5.3-4)
trixie: resolved (fixed in 3.5.3-4)
GHSA
GHSA-3ccg-r3xv-q4cg: The gnutls_ocsp_resp_check_crt function in lib/x509/ocsp
ghsa_unreviewed·2022-05-14
CVE-2016-7444 [HIGH] GHSA-3ccg-r3xv-q4cg: The gnutls_ocsp_resp_check_crt function in lib/x509/ocsp
The gnutls_ocsp_resp_check_crt function in lib/x509/ocsp.c in GnuTLS before 3.4.15 and 3.5.x before 3.5.4 does not verify the serial length of an OCSP response, which might allow remote attackers to bypass an intended certificate validation mechanism via vectors involving trailing bytes left by gnutls_malloc.
OSV
gnutls26 vulnerability
osv·2017-03-20·CVSS 7.5
CVE-2016-8610 [HIGH] gnutls26 vulnerability
gnutls26 vulnerability
USN-3183-1 fixed CVE-2016-8610 in GnuTLS in Ubuntu 16.04 LTS and Ubuntu
16.10. This update provides the corresponding update for Ubuntu 12.04 LTS
and Ubuntu 14.04 LTS.
Original advisory details:
Stefan Buehler discovered that GnuTLS incorrectly verified the serial
length of OCSP responses. A remote attacker could possibly use this issue
to bypass certain certificate validation measures. This issue only applied
to Ubuntu 16.04 LTS. (CVE-2016-7444)
Shi Lei discovered that GnuTLS incorrectly handled certain warning alerts.
A remote attacker could possibly use this issue to cause GnuTLS to hang,
resulting in a denial of service. This issue has only been addressed in
Ubuntu 16.04 LTS and Ubuntu 16.10. (CVE-2016-8610)
It was discovered that GnuTLS incorrectly decoded
OSV
gnutls26, gnutls28 vulnerabilities
osv·2017-02-01·CVSS 7.5
CVE-2016-7444 [HIGH] gnutls26, gnutls28 vulnerabilities
gnutls26, gnutls28 vulnerabilities
Stefan Buehler discovered that GnuTLS incorrectly verified the serial
length of OCSP responses. A remote attacker could possibly use this issue
to bypass certain certificate validation measures. This issue only applied
to Ubuntu 16.04 LTS. (CVE-2016-7444)
Shi Lei discovered that GnuTLS incorrectly handled certain warning alerts.
A remote attacker could possibly use this issue to cause GnuTLS to hang,
resulting in a denial of service. This issue has only been addressed in
Ubuntu 16.04 LTS and Ubuntu 16.10. (CVE-2016-8610)
It was discovered that GnuTLS incorrectly decoded X.509 certificates with a
Proxy Certificate Information extension. A remote attacker could use this
issue to cause GnuTLS to crash, resulting in a denial of service, or
possibly execute
OSV
CVE-2016-7444: The gnutls_ocsp_resp_check_crt function in lib/x509/ocsp
osv·2016-09-27·CVSS 7.5
CVE-2016-7444 [HIGH] CVE-2016-7444: The gnutls_ocsp_resp_check_crt function in lib/x509/ocsp
The gnutls_ocsp_resp_check_crt function in lib/x509/ocsp.c in GnuTLS before 3.4.15 and 3.5.x before 3.5.4 does not verify the serial length of an OCSP response, which might allow remote attackers to bypass an intended certificate validation mechanism via vectors involving trailing bytes left by gnutls_malloc.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-7444 gnutls: Incorrect certificate validation when using OCSP responses (GNUTLS-SA-2016-3)
bugzilla·2016-09-08·CVSS 7.5
CVE-2016-7444 [HIGH] CVE-2016-7444 gnutls: Incorrect certificate validation when using OCSP responses (GNUTLS-SA-2016-3)
CVE-2016-7444 gnutls: Incorrect certificate validation when using OCSP responses (GNUTLS-SA-2016-3)
It was found an issue in certificate validation using OCSP responses caused by not verifying the serial length, which can falsely report a certificate as valid.
Upstream patch:
https://gitlab.com/gnutls/gnutls/commit/964632f37dfdfb914ebc5e49db4fa29af35b1de9
External References:
https://www.gnutls.org/security.html
https://lists.gnupg.org/pipermail/gnutls-devel/2016-September/008146.html
Discussion:
Created mingw-gnutls tracking bugs for this issue:
Affects: fedora-all [bug 1374269]
Affects: epel-7 [bug 1374270]
---
Created gnutls tracking bugs for this issue:
Affects: fedora-all [bug 1374267]
---
gnutls-3.5.4-1.fc25 has been pushed to the Fedora 25 stable repository. If problems
Bugzilla
CVE-2016-7444 gnutls: Incorrect certificate validation when using OCSP responses (GNUTLS-SA-2016-3) [fedora-all]
bugzilla·2016-09-08·CVSS 7.5
CVE-2016-7444 [HIGH] CVE-2016-7444 gnutls: Incorrect certificate validation when using OCSP responses (GNUTLS-SA-2016-3) [fedora-all]
CVE-2016-7444 gnutls: Incorrect certificate validation when using OCSP responses (GNUTLS-SA-2016-3) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affe
Bugzilla
CVE-2016-7444 mingw-gnutls: gnutls: Incorrect certificate validation when using OCSP responses (GNUTLS-SA-2016-3) [fedora-all]
bugzilla·2016-09-08·CVSS 7.5
CVE-2016-7444 [HIGH] CVE-2016-7444 mingw-gnutls: gnutls: Incorrect certificate validation when using OCSP responses (GNUTLS-SA-2016-3) [fedora-all]
CVE-2016-7444 mingw-gnutls: gnutls: Incorrect certificate validation when using OCSP responses (GNUTLS-SA-2016-3) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: t
Bugzilla
CVE-2016-7444 mingw-gnutls: gnutls: Incorrect certificate validation when using OCSP responses (GNUTLS-SA-2016-3) [epel-7]
bugzilla·2016-09-08·CVSS 7.5
CVE-2016-7444 [HIGH] CVE-2016-7444 mingw-gnutls: gnutls: Incorrect certificate validation when using OCSP responses (GNUTLS-SA-2016-3) [epel-7]
CVE-2016-7444 mingw-gnutls: gnutls: Incorrect certificate validation when using OCSP responses (GNUTLS-SA-2016-3) [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
[bug a
http://lists.opensuse.org/opensuse-security-announce/2017-02/msg00005.htmlhttp://www.securityfocus.com/bid/92893https://access.redhat.com/errata/RHSA-2017:2292https://gitlab.com/gnutls/gnutls/commit/964632f37dfdfb914ebc5e49db4fa29af35b1de9https://lists.gnupg.org/pipermail/gnutls-devel/2016-September/008146.htmlhttps://www.gnutls.org/security.htmlhttp://lists.opensuse.org/opensuse-security-announce/2017-02/msg00005.htmlhttp://www.securityfocus.com/bid/92893https://access.redhat.com/errata/RHSA-2017:2292https://gitlab.com/gnutls/gnutls/commit/964632f37dfdfb914ebc5e49db4fa29af35b1de9https://lists.gnupg.org/pipermail/gnutls-devel/2016-September/008146.htmlhttps://www.gnutls.org/security.html
2016-09-27
Published