CVE-2017-5334
published 2017-03-24CVE-2017-5334: Double free vulnerability in the gnutls_x509_ext_import_proxy function in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allows remote attackers to have…
PriorityP355critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
32.75%
98.2th percentile
Double free vulnerability in the gnutls_x509_ext_import_proxy function in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allows remote attackers to have unspecified impact via crafted policy language information in an X.509 certificate with a Proxy Certificate Information extension.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | gnutls28 | < gnutls28 3.5.8-1 (bookworm) | gnutls28 3.5.8-1 (bookworm) |
| gnu | gnutls | <= 3.3.25 | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| opensuse | leap | — | — |
| opensuse | leap | — | — |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
GnuTLS vulnerability
vendor_ubuntu·2017-03-20·CVSS 7.5
CVE-2016-8610 [HIGH] GnuTLS vulnerability
Title: GnuTLS vulnerability
Summary: GnuTLS could be made to hang if it received specially crafted network
traffic.
USN-3183-1 fixed CVE-2016-8610 in GnuTLS in Ubuntu 16.04 LTS and Ubuntu
16.10. This update provides the corresponding update for Ubuntu 12.04 LTS
and Ubuntu 14.04 LTS.
Original advisory details:
Stefan Buehler discovered that GnuTLS incorrectly verified the serial
length of OCSP responses. A remote attacker could possibly use this issue
to bypass certain certificate validation measures. This issue only applied
to Ubuntu 16.04 LTS. (CVE-2016-7444)
Shi Lei discovered that GnuTLS incorrectly handled certain warning alerts.
A remote attacker could possibly use this issue to cause GnuTLS to hang,
resulting in a denial of service. This issue has only been addressed in
Ubuntu 1
Ubuntu
GnuTLS vulnerabilities
vendor_ubuntu·2017-02-01·CVSS 7.5
CVE-2016-7444 [HIGH] GnuTLS vulnerabilities
Title: GnuTLS vulnerabilities
Summary: Several security issues were fixed in GnuTLS.
Stefan Buehler discovered that GnuTLS incorrectly verified the serial
length of OCSP responses. A remote attacker could possibly use this issue
to bypass certain certificate validation measures. This issue only applied
to Ubuntu 16.04 LTS. (CVE-2016-7444)
Shi Lei discovered that GnuTLS incorrectly handled certain warning alerts.
A remote attacker could possibly use this issue to cause GnuTLS to hang,
resulting in a denial of service. This issue has only been addressed in
Ubuntu 16.04 LTS and Ubuntu 16.10. (CVE-2016-8610)
It was discovered that GnuTLS incorrectly decoded X.509 certificates with a
Proxy Certificate Information extension. A remote attacker could use this
issue to cause GnuTLS to crash, re
Red Hat
gnutls: Double-free while decoding crafted X.509 certificates
vendor_redhat·2017-01-10·CVSS 9.8
CVE-2017-5334 [CRITICAL] CWE-416 gnutls: Double-free while decoding crafted X.509 certificates
gnutls: Double-free while decoding crafted X.509 certificates
Double free vulnerability in the gnutls_x509_ext_import_proxy function in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allows remote attackers to have unspecified impact via crafted policy language information in an X.509 certificate with a Proxy Certificate Information extension.
A double-free flaw was found in the way GnuTLS parsed certain X.509 certificates with Proxy Certificate Information extension. An attacker could create a specially-crafted certificate which, when processed by an application compiled against GnuTLS, could cause that application to crash.
Package: gnutls (Red Hat Enterprise Linux 5) - Not affected
Package: gnutls (Red Hat Enterprise Linux 6) - Not affected
Debian
CVE-2017-5334: gnutls28 - Double free vulnerability in the gnutls_x509_ext_import_proxy function in GnuTLS...
vendor_debian·2017·CVSS 9.8
CVE-2017-5334 [CRITICAL] CVE-2017-5334: gnutls28 - Double free vulnerability in the gnutls_x509_ext_import_proxy function in GnuTLS...
Double free vulnerability in the gnutls_x509_ext_import_proxy function in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allows remote attackers to have unspecified impact via crafted policy language information in an X.509 certificate with a Proxy Certificate Information extension.
Scope: local
bookworm: resolved (fixed in 3.5.8-1)
bullseye: resolved (fixed in 3.5.8-1)
forky: resolved (fixed in 3.5.8-1)
sid: resolved (fixed in 3.5.8-1)
trixie: resolved (fixed in 3.5.8-1)
GHSA
GHSA-xwcr-3xw9-7333: Double free vulnerability in the gnutls_x509_ext_import_proxy function in GnuTLS before 3
ghsa_unreviewed·2022-05-14
CVE-2017-5334 [CRITICAL] CWE-415 GHSA-xwcr-3xw9-7333: Double free vulnerability in the gnutls_x509_ext_import_proxy function in GnuTLS before 3
Double free vulnerability in the gnutls_x509_ext_import_proxy function in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allows remote attackers to have unspecified impact via crafted policy language information in an X.509 certificate with a Proxy Certificate Information extension.
OSV
CVE-2017-5334: Double free vulnerability in the gnutls_x509_ext_import_proxy function in GnuTLS before 3
osv·2017-03-24·CVSS 9.8
CVE-2017-5334 [CRITICAL] CVE-2017-5334: Double free vulnerability in the gnutls_x509_ext_import_proxy function in GnuTLS before 3
Double free vulnerability in the gnutls_x509_ext_import_proxy function in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allows remote attackers to have unspecified impact via crafted policy language information in an X.509 certificate with a Proxy Certificate Information extension.
OSV
gnutls26 vulnerability
osv·2017-03-20·CVSS 7.5
CVE-2016-8610 [HIGH] gnutls26 vulnerability
gnutls26 vulnerability
USN-3183-1 fixed CVE-2016-8610 in GnuTLS in Ubuntu 16.04 LTS and Ubuntu
16.10. This update provides the corresponding update for Ubuntu 12.04 LTS
and Ubuntu 14.04 LTS.
Original advisory details:
Stefan Buehler discovered that GnuTLS incorrectly verified the serial
length of OCSP responses. A remote attacker could possibly use this issue
to bypass certain certificate validation measures. This issue only applied
to Ubuntu 16.04 LTS. (CVE-2016-7444)
Shi Lei discovered that GnuTLS incorrectly handled certain warning alerts.
A remote attacker could possibly use this issue to cause GnuTLS to hang,
resulting in a denial of service. This issue has only been addressed in
Ubuntu 16.04 LTS and Ubuntu 16.10. (CVE-2016-8610)
It was discovered that GnuTLS incorrectly decoded
OSV
gnutls26, gnutls28 vulnerabilities
osv·2017-02-01·CVSS 7.5
CVE-2016-7444 [HIGH] gnutls26, gnutls28 vulnerabilities
gnutls26, gnutls28 vulnerabilities
Stefan Buehler discovered that GnuTLS incorrectly verified the serial
length of OCSP responses. A remote attacker could possibly use this issue
to bypass certain certificate validation measures. This issue only applied
to Ubuntu 16.04 LTS. (CVE-2016-7444)
Shi Lei discovered that GnuTLS incorrectly handled certain warning alerts.
A remote attacker could possibly use this issue to cause GnuTLS to hang,
resulting in a denial of service. This issue has only been addressed in
Ubuntu 16.04 LTS and Ubuntu 16.10. (CVE-2016-8610)
It was discovered that GnuTLS incorrectly decoded X.509 certificates with a
Proxy Certificate Information extension. A remote attacker could use this
issue to cause GnuTLS to crash, resulting in a denial of service, or
possibly execute
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-5334 gnutls30: gnutls: Double-free while decoding crafted X.509 certificates [epel-6]
bugzilla·2017-01-10·CVSS 9.8
CVE-2017-5334 [CRITICAL] CVE-2017-5334 gnutls30: gnutls: Double-free while decoding crafted X.509 certificates [epel-6]
CVE-2017-5334 gnutls30: gnutls: Double-free while decoding crafted X.509 certificates [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-6.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
gnutls30-3.5.8-1.el6 has b
Bugzilla
CVE-2017-5334 gnutls: Double-free while decoding crafted X.509 certificates
bugzilla·2017-01-10·CVSS 9.8
CVE-2017-5334 [CRITICAL] CVE-2017-5334 gnutls: Double-free while decoding crafted X.509 certificates
CVE-2017-5334 gnutls: Double-free while decoding crafted X.509 certificates
It was found that decoding a specially crafted X.509 certificate with Proxy Certificate Information extension present could lead to a double free. This issue was fixed in GnuTLS 3.3.26 and 3.5.8.
External References:
https://gnutls.org/security.html#GNUTLS-SA-2017-1
Upstream patch:
https://gitlab.com/gnutls/gnutls/commit/c5aaa488a3d6df712dc8dff23a049133cab5ec1b
Discussion:
Created gnutls tracking bugs for this issue:
Affects: fedora-all [bug 1411838]
---
This was addressed in F25 with https://bodhi.fedoraproject.org/updates/FEDORA-2017-88f1664dd4
---
Created gnutls30 tracking bugs for this issue:
Affects: epel-6 [bug 1411846]
---
CVE assignment:
http://seclists.org/oss-sec/2017/q1/57
---
This issu
Bugzilla
CVE-2017-5334 CVE-2017-5335 CVE-2017-5336 CVE-2017-5337 gnutls: various flaws [fedora-all]
bugzilla·2017-01-10·CVSS 9.8
CVE-2017-5334 [CRITICAL] CVE-2017-5334 CVE-2017-5335 CVE-2017-5336 CVE-2017-5337 gnutls: various flaws [fedora-all]
CVE-2017-5334 CVE-2017-5335 CVE-2017-5336 CVE-2017-5337 gnutls: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple suppo
http://lists.opensuse.org/opensuse-security-announce/2017-02/msg00005.htmlhttp://www.openwall.com/lists/oss-security/2017/01/10/7http://www.openwall.com/lists/oss-security/2017/01/11/4http://www.securityfocus.com/bid/95370http://www.securitytracker.com/id/1037576https://access.redhat.com/errata/RHSA-2017:2292https://gitlab.com/gnutls/gnutls/commit/c5aaa488a3d6df712dc8dff23a049133cab5ec1bhttps://gnutls.org/security.html#GNUTLS-SA-2017-1https://security.gentoo.org/glsa/201702-04http://lists.opensuse.org/opensuse-security-announce/2017-02/msg00005.htmlhttp://www.openwall.com/lists/oss-security/2017/01/10/7http://www.openwall.com/lists/oss-security/2017/01/11/4http://www.securityfocus.com/bid/95370http://www.securitytracker.com/id/1037576https://access.redhat.com/errata/RHSA-2017:2292https://gitlab.com/gnutls/gnutls/commit/c5aaa488a3d6df712dc8dff23a049133cab5ec1bhttps://gnutls.org/security.html#GNUTLS-SA-2017-1https://security.gentoo.org/glsa/201702-04
2017-03-24
Published