CVE-2017-5335
published 2017-03-24CVE-2017-5335: The stream reading functions in lib/opencdk/read-packet.c in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allow remote attackers to cause a denial of service…
PriorityP338high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
8.01%
94.2th percentile
The stream reading functions in lib/opencdk/read-packet.c in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allow remote attackers to cause a denial of service (out-of-memory error and crash) via a crafted OpenPGP certificate.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | gnutls28 | < gnutls28 3.5.8-1 (bookworm) | gnutls28 3.5.8-1 (bookworm) |
| gnu | gnutls | <= 3.3.25 | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| opensuse | leap | — | — |
| opensuse | leap | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
GnuTLS vulnerability
vendor_ubuntu·2017-03-20·CVSS 7.5
CVE-2016-8610 [HIGH] GnuTLS vulnerability
Title: GnuTLS vulnerability
Summary: GnuTLS could be made to hang if it received specially crafted network
traffic.
USN-3183-1 fixed CVE-2016-8610 in GnuTLS in Ubuntu 16.04 LTS and Ubuntu
16.10. This update provides the corresponding update for Ubuntu 12.04 LTS
and Ubuntu 14.04 LTS.
Original advisory details:
Stefan Buehler discovered that GnuTLS incorrectly verified the serial
length of OCSP responses. A remote attacker could possibly use this issue
to bypass certain certificate validation measures. This issue only applied
to Ubuntu 16.04 LTS. (CVE-2016-7444)
Shi Lei discovered that GnuTLS incorrectly handled certain warning alerts.
A remote attacker could possibly use this issue to cause GnuTLS to hang,
resulting in a denial of service. This issue has only been addressed in
Ubuntu 1
Ubuntu
GnuTLS vulnerabilities
vendor_ubuntu·2017-02-01·CVSS 7.5
CVE-2016-7444 [HIGH] GnuTLS vulnerabilities
Title: GnuTLS vulnerabilities
Summary: Several security issues were fixed in GnuTLS.
Stefan Buehler discovered that GnuTLS incorrectly verified the serial
length of OCSP responses. A remote attacker could possibly use this issue
to bypass certain certificate validation measures. This issue only applied
to Ubuntu 16.04 LTS. (CVE-2016-7444)
Shi Lei discovered that GnuTLS incorrectly handled certain warning alerts.
A remote attacker could possibly use this issue to cause GnuTLS to hang,
resulting in a denial of service. This issue has only been addressed in
Ubuntu 16.04 LTS and Ubuntu 16.10. (CVE-2016-8610)
It was discovered that GnuTLS incorrectly decoded X.509 certificates with a
Proxy Certificate Information extension. A remote attacker could use this
issue to cause GnuTLS to crash, re
Red Hat
gnutls: Out of memory while parsing crafted OpenPGP certificate
vendor_redhat·2017-01-10·CVSS 7.5
CVE-2017-5335 [HIGH] CWE-400 gnutls: Out of memory while parsing crafted OpenPGP certificate
gnutls: Out of memory while parsing crafted OpenPGP certificate
The stream reading functions in lib/opencdk/read-packet.c in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allow remote attackers to cause a denial of service (out-of-memory error and crash) via a crafted OpenPGP certificate.
Package: gnutls (Red Hat Enterprise Linux 5) - Will not fix
Debian
CVE-2017-5335: gnutls28 - The stream reading functions in lib/opencdk/read-packet.c in GnuTLS before 3.3.2...
vendor_debian·2017·CVSS 7.5
CVE-2017-5335 [HIGH] CVE-2017-5335: gnutls28 - The stream reading functions in lib/opencdk/read-packet.c in GnuTLS before 3.3.2...
The stream reading functions in lib/opencdk/read-packet.c in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allow remote attackers to cause a denial of service (out-of-memory error and crash) via a crafted OpenPGP certificate.
Scope: local
bookworm: resolved (fixed in 3.5.8-1)
bullseye: resolved (fixed in 3.5.8-1)
forky: resolved (fixed in 3.5.8-1)
sid: resolved (fixed in 3.5.8-1)
trixie: resolved (fixed in 3.5.8-1)
GHSA
GHSA-3wcr-vccv-4fcx: The stream reading functions in lib/opencdk/read-packet
ghsa_unreviewed·2022-05-14
CVE-2017-5335 [HIGH] CWE-125 GHSA-3wcr-vccv-4fcx: The stream reading functions in lib/opencdk/read-packet
The stream reading functions in lib/opencdk/read-packet.c in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allow remote attackers to cause a denial of service (out-of-memory error and crash) via a crafted OpenPGP certificate.
OSV
CVE-2017-5335: The stream reading functions in lib/opencdk/read-packet
osv·2017-03-24·CVSS 7.5
CVE-2017-5335 [HIGH] CVE-2017-5335: The stream reading functions in lib/opencdk/read-packet
The stream reading functions in lib/opencdk/read-packet.c in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allow remote attackers to cause a denial of service (out-of-memory error and crash) via a crafted OpenPGP certificate.
OSV
gnutls26 vulnerability
osv·2017-03-20·CVSS 7.5
CVE-2016-8610 [HIGH] gnutls26 vulnerability
gnutls26 vulnerability
USN-3183-1 fixed CVE-2016-8610 in GnuTLS in Ubuntu 16.04 LTS and Ubuntu
16.10. This update provides the corresponding update for Ubuntu 12.04 LTS
and Ubuntu 14.04 LTS.
Original advisory details:
Stefan Buehler discovered that GnuTLS incorrectly verified the serial
length of OCSP responses. A remote attacker could possibly use this issue
to bypass certain certificate validation measures. This issue only applied
to Ubuntu 16.04 LTS. (CVE-2016-7444)
Shi Lei discovered that GnuTLS incorrectly handled certain warning alerts.
A remote attacker could possibly use this issue to cause GnuTLS to hang,
resulting in a denial of service. This issue has only been addressed in
Ubuntu 16.04 LTS and Ubuntu 16.10. (CVE-2016-8610)
It was discovered that GnuTLS incorrectly decoded
OSV
gnutls26, gnutls28 vulnerabilities
osv·2017-02-01·CVSS 7.5
CVE-2016-7444 [HIGH] gnutls26, gnutls28 vulnerabilities
gnutls26, gnutls28 vulnerabilities
Stefan Buehler discovered that GnuTLS incorrectly verified the serial
length of OCSP responses. A remote attacker could possibly use this issue
to bypass certain certificate validation measures. This issue only applied
to Ubuntu 16.04 LTS. (CVE-2016-7444)
Shi Lei discovered that GnuTLS incorrectly handled certain warning alerts.
A remote attacker could possibly use this issue to cause GnuTLS to hang,
resulting in a denial of service. This issue has only been addressed in
Ubuntu 16.04 LTS and Ubuntu 16.10. (CVE-2016-8610)
It was discovered that GnuTLS incorrectly decoded X.509 certificates with a
Proxy Certificate Information extension. A remote attacker could use this
issue to cause GnuTLS to crash, resulting in a denial of service, or
possibly execute
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-5335 gnutls: Out of memory while parsing crafted OpenPGP certificate
bugzilla·2017-01-11·CVSS 7.5
CVE-2017-5335 [HIGH] CVE-2017-5335 gnutls: Out of memory while parsing crafted OpenPGP certificate
CVE-2017-5335 gnutls: Out of memory while parsing crafted OpenPGP certificate
A vulnerability was found in gnutls. There was an insufficient error checking in the stream reading functions. While parsing a maliciously crafted OpenPGP certificate an out of memory error could occur.
References:
http://seclists.org/oss-sec/2017/q1/51
https://gnutls.org/security.html#GNUTLS-SA-2017-2
Upstream patch:
https://gitlab.com/gnutls/gnutls/commit/49be4f7b82eba2363bb8d4090950dad976a77a3a
Discussion:
Created gnutls tracking bugs for this issue:
Affects: fedora-all [bug 1411838]
---
Created gnutls30 tracking bugs for this issue:
Affects: epel-6 [bug 1411845]
---
Reproducer at: https://gitlab.com/gnutls/gnutls/commit/65ee81db857d3b44cec76aa94361abe5427430d8
---
Maps to: https://bugs.chromium
Bugzilla
CVE-2017-5335 CVE-2017-5336 CVE-2017-5337 gnutls30: various flaws [epel-6]
bugzilla·2017-01-10·CVSS 7.5
CVE-2017-5335 [HIGH] CVE-2017-5335 CVE-2017-5336 CVE-2017-5337 gnutls30: various flaws [epel-6]
CVE-2017-5335 CVE-2017-5336 CVE-2017-5337 gnutls30: various flaws [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-6.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Adding parent bug 1412236 (for CVE-2017-5336).
Bugzilla
CVE-2017-5334 CVE-2017-5335 CVE-2017-5336 CVE-2017-5337 gnutls: various flaws [fedora-all]
bugzilla·2017-01-10·CVSS 9.8
CVE-2017-5334 [CRITICAL] CVE-2017-5334 CVE-2017-5335 CVE-2017-5336 CVE-2017-5337 gnutls: various flaws [fedora-all]
CVE-2017-5334 CVE-2017-5335 CVE-2017-5336 CVE-2017-5337 gnutls: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple suppo
http://lists.opensuse.org/opensuse-security-announce/2017-02/msg00005.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0574.htmlhttp://www.openwall.com/lists/oss-security/2017/01/10/7http://www.openwall.com/lists/oss-security/2017/01/11/4http://www.securityfocus.com/bid/95374http://www.securitytracker.com/id/1037576https://access.redhat.com/errata/RHSA-2017:2292https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=337https://gitlab.com/gnutls/gnutls/commit/49be4f7b82eba2363bb8d4090950dad976a77a3ahttps://gnutls.org/security.html#GNUTLS-SA-2017-2https://security.gentoo.org/glsa/201702-04http://lists.opensuse.org/opensuse-security-announce/2017-02/msg00005.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0574.htmlhttp://www.openwall.com/lists/oss-security/2017/01/10/7http://www.openwall.com/lists/oss-security/2017/01/11/4http://www.securityfocus.com/bid/95374http://www.securitytracker.com/id/1037576https://access.redhat.com/errata/RHSA-2017:2292https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=337https://gitlab.com/gnutls/gnutls/commit/49be4f7b82eba2363bb8d4090950dad976a77a3ahttps://gnutls.org/security.html#GNUTLS-SA-2017-2https://security.gentoo.org/glsa/201702-04
2017-03-24
Published