CVE-2017-5336
published 2017-03-24CVE-2017-5336: Stack-based buffer overflow in the cdk_pk_get_keyid function in lib/opencdk/pubkey.c in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allows remote attackers to…
PriorityP350critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
7.07%
93.5th percentile
Stack-based buffer overflow in the cdk_pk_get_keyid function in lib/opencdk/pubkey.c in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allows remote attackers to have unspecified impact via a crafted OpenPGP certificate.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | gnutls28 | < gnutls28 3.5.8-1 (bookworm) | gnutls28 3.5.8-1 (bookworm) |
| gnu | gnutls | <= 3.3.25 | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| opensuse | leap | — | — |
| opensuse | leap | — | — |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
GnuTLS vulnerability
vendor_ubuntu·2017-03-20·CVSS 7.5
CVE-2016-8610 [HIGH] GnuTLS vulnerability
Title: GnuTLS vulnerability
Summary: GnuTLS could be made to hang if it received specially crafted network
traffic.
USN-3183-1 fixed CVE-2016-8610 in GnuTLS in Ubuntu 16.04 LTS and Ubuntu
16.10. This update provides the corresponding update for Ubuntu 12.04 LTS
and Ubuntu 14.04 LTS.
Original advisory details:
Stefan Buehler discovered that GnuTLS incorrectly verified the serial
length of OCSP responses. A remote attacker could possibly use this issue
to bypass certain certificate validation measures. This issue only applied
to Ubuntu 16.04 LTS. (CVE-2016-7444)
Shi Lei discovered that GnuTLS incorrectly handled certain warning alerts.
A remote attacker could possibly use this issue to cause GnuTLS to hang,
resulting in a denial of service. This issue has only been addressed in
Ubuntu 1
Ubuntu
GnuTLS vulnerabilities
vendor_ubuntu·2017-02-01·CVSS 7.5
CVE-2016-7444 [HIGH] GnuTLS vulnerabilities
Title: GnuTLS vulnerabilities
Summary: Several security issues were fixed in GnuTLS.
Stefan Buehler discovered that GnuTLS incorrectly verified the serial
length of OCSP responses. A remote attacker could possibly use this issue
to bypass certain certificate validation measures. This issue only applied
to Ubuntu 16.04 LTS. (CVE-2016-7444)
Shi Lei discovered that GnuTLS incorrectly handled certain warning alerts.
A remote attacker could possibly use this issue to cause GnuTLS to hang,
resulting in a denial of service. This issue has only been addressed in
Ubuntu 16.04 LTS and Ubuntu 16.10. (CVE-2016-8610)
It was discovered that GnuTLS incorrectly decoded X.509 certificates with a
Proxy Certificate Information extension. A remote attacker could use this
issue to cause GnuTLS to crash, re
Red Hat
gnutls: Stack overflow in cdk_pk_get_keyid
vendor_redhat·2017-01-10·CVSS 9.8
CVE-2017-5336 [CRITICAL] CWE-121 gnutls: Stack overflow in cdk_pk_get_keyid
gnutls: Stack overflow in cdk_pk_get_keyid
Stack-based buffer overflow in the cdk_pk_get_keyid function in lib/opencdk/pubkey.c in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allows remote attackers to have unspecified impact via a crafted OpenPGP certificate.
Package: gnutls (Red Hat Enterprise Linux 5) - Will not fix
Debian
CVE-2017-5336: gnutls28 - Stack-based buffer overflow in the cdk_pk_get_keyid function in lib/opencdk/pubk...
vendor_debian·2017·CVSS 9.8
CVE-2017-5336 [CRITICAL] CVE-2017-5336: gnutls28 - Stack-based buffer overflow in the cdk_pk_get_keyid function in lib/opencdk/pubk...
Stack-based buffer overflow in the cdk_pk_get_keyid function in lib/opencdk/pubkey.c in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allows remote attackers to have unspecified impact via a crafted OpenPGP certificate.
Scope: local
bookworm: resolved (fixed in 3.5.8-1)
bullseye: resolved (fixed in 3.5.8-1)
forky: resolved (fixed in 3.5.8-1)
sid: resolved (fixed in 3.5.8-1)
trixie: resolved (fixed in 3.5.8-1)
GHSA
GHSA-93p2-4472-9gj5: Stack-based buffer overflow in the cdk_pk_get_keyid function in lib/opencdk/pubkey
ghsa_unreviewed·2022-05-14
CVE-2017-5336 [CRITICAL] CWE-119 GHSA-93p2-4472-9gj5: Stack-based buffer overflow in the cdk_pk_get_keyid function in lib/opencdk/pubkey
Stack-based buffer overflow in the cdk_pk_get_keyid function in lib/opencdk/pubkey.c in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allows remote attackers to have unspecified impact via a crafted OpenPGP certificate.
OSV
CVE-2017-5336: Stack-based buffer overflow in the cdk_pk_get_keyid function in lib/opencdk/pubkey
osv·2017-03-24·CVSS 9.8
CVE-2017-5336 [CRITICAL] CVE-2017-5336: Stack-based buffer overflow in the cdk_pk_get_keyid function in lib/opencdk/pubkey
Stack-based buffer overflow in the cdk_pk_get_keyid function in lib/opencdk/pubkey.c in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allows remote attackers to have unspecified impact via a crafted OpenPGP certificate.
OSV
gnutls26 vulnerability
osv·2017-03-20·CVSS 7.5
CVE-2016-8610 [HIGH] gnutls26 vulnerability
gnutls26 vulnerability
USN-3183-1 fixed CVE-2016-8610 in GnuTLS in Ubuntu 16.04 LTS and Ubuntu
16.10. This update provides the corresponding update for Ubuntu 12.04 LTS
and Ubuntu 14.04 LTS.
Original advisory details:
Stefan Buehler discovered that GnuTLS incorrectly verified the serial
length of OCSP responses. A remote attacker could possibly use this issue
to bypass certain certificate validation measures. This issue only applied
to Ubuntu 16.04 LTS. (CVE-2016-7444)
Shi Lei discovered that GnuTLS incorrectly handled certain warning alerts.
A remote attacker could possibly use this issue to cause GnuTLS to hang,
resulting in a denial of service. This issue has only been addressed in
Ubuntu 16.04 LTS and Ubuntu 16.10. (CVE-2016-8610)
It was discovered that GnuTLS incorrectly decoded
OSV
gnutls26, gnutls28 vulnerabilities
osv·2017-02-01·CVSS 7.5
CVE-2016-7444 [HIGH] gnutls26, gnutls28 vulnerabilities
gnutls26, gnutls28 vulnerabilities
Stefan Buehler discovered that GnuTLS incorrectly verified the serial
length of OCSP responses. A remote attacker could possibly use this issue
to bypass certain certificate validation measures. This issue only applied
to Ubuntu 16.04 LTS. (CVE-2016-7444)
Shi Lei discovered that GnuTLS incorrectly handled certain warning alerts.
A remote attacker could possibly use this issue to cause GnuTLS to hang,
resulting in a denial of service. This issue has only been addressed in
Ubuntu 16.04 LTS and Ubuntu 16.10. (CVE-2016-8610)
It was discovered that GnuTLS incorrectly decoded X.509 certificates with a
Proxy Certificate Information extension. A remote attacker could use this
issue to cause GnuTLS to crash, resulting in a denial of service, or
possibly execute
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-5336 gnutls: Stack overflow in cdk_pk_get_keyid
bugzilla·2017-01-11·CVSS 9.8
CVE-2017-5336 [CRITICAL] CVE-2017-5336 gnutls: Stack overflow in cdk_pk_get_keyid
CVE-2017-5336 gnutls: Stack overflow in cdk_pk_get_keyid
A vulnerability was found in gnutls. A stack overflow could occur in opencdk in the cdk_pk_get_keyid function. A memory corruption could occur when parsing a maliciously crafted OpenPGP certificate.
References:
http://seclists.org/oss-sec/2017/q1/51
https://gnutls.org/security.html#GNUTLS-SA-2017-2
Upstream patch:
https://gitlab.com/gnutls/gnutls/commit/5140422e0d7319a8e2fe07f02cbcafc4d6538732
Discussion:
Created gnutls tracking bugs for this issue:
Affects: fedora-all [bug 1411838]
---
Created gnutls30 tracking bugs for this issue:
Affects: epel-6 [bug 1411845]
---
Reproducer at:
https://gitlab.com/gnutls/gnutls/commit/611098e2f01fd8c3a5a625d61f26c56fcb3d770c
---
Maps to: https://bugs.chromium.org/p/oss-fuzz/issues/de
Bugzilla
CVE-2017-5335 CVE-2017-5336 CVE-2017-5337 gnutls30: various flaws [epel-6]
bugzilla·2017-01-10·CVSS 7.5
CVE-2017-5335 [HIGH] CVE-2017-5335 CVE-2017-5336 CVE-2017-5337 gnutls30: various flaws [epel-6]
CVE-2017-5335 CVE-2017-5336 CVE-2017-5337 gnutls30: various flaws [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-6.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Adding parent bug 1412236 (for CVE-2017-5336).
Bugzilla
CVE-2017-5334 CVE-2017-5335 CVE-2017-5336 CVE-2017-5337 gnutls: various flaws [fedora-all]
bugzilla·2017-01-10·CVSS 9.8
CVE-2017-5334 [CRITICAL] CVE-2017-5334 CVE-2017-5335 CVE-2017-5336 CVE-2017-5337 gnutls: various flaws [fedora-all]
CVE-2017-5334 CVE-2017-5335 CVE-2017-5336 CVE-2017-5337 gnutls: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple suppo
http://lists.opensuse.org/opensuse-security-announce/2017-02/msg00005.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0574.htmlhttp://www.openwall.com/lists/oss-security/2017/01/10/7http://www.openwall.com/lists/oss-security/2017/01/11/4http://www.securityfocus.com/bid/95377http://www.securitytracker.com/id/1037576https://access.redhat.com/errata/RHSA-2017:2292https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=340https://gitlab.com/gnutls/gnutls/commit/5140422e0d7319a8e2fe07f02cbcafc4d6538732https://gnutls.org/security.html#GNUTLS-SA-2017-2https://security.gentoo.org/glsa/201702-04http://lists.opensuse.org/opensuse-security-announce/2017-02/msg00005.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0574.htmlhttp://www.openwall.com/lists/oss-security/2017/01/10/7http://www.openwall.com/lists/oss-security/2017/01/11/4http://www.securityfocus.com/bid/95377http://www.securitytracker.com/id/1037576https://access.redhat.com/errata/RHSA-2017:2292https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=340https://gitlab.com/gnutls/gnutls/commit/5140422e0d7319a8e2fe07f02cbcafc4d6538732https://gnutls.org/security.html#GNUTLS-SA-2017-2https://security.gentoo.org/glsa/201702-04
2017-03-24
Published