CVE-2017-5337
published 2017-03-24CVE-2017-5337: Multiple heap-based buffer overflows in the read_attribute function in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allow remote attackers to have unspecified…
PriorityP348critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
6.18%
92.7th percentile
Multiple heap-based buffer overflows in the read_attribute function in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allow remote attackers to have unspecified impact via a crafted OpenPGP certificate.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | gnutls28 | < gnutls28 3.5.8-1 (bookworm) | gnutls28 3.5.8-1 (bookworm) |
| gnu | gnutls | <= 3.3.25 | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| opensuse | leap | — | — |
| opensuse | leap | — | — |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
GnuTLS vulnerability
vendor_ubuntu·2017-03-20·CVSS 7.5
CVE-2016-8610 [HIGH] GnuTLS vulnerability
Title: GnuTLS vulnerability
Summary: GnuTLS could be made to hang if it received specially crafted network
traffic.
USN-3183-1 fixed CVE-2016-8610 in GnuTLS in Ubuntu 16.04 LTS and Ubuntu
16.10. This update provides the corresponding update for Ubuntu 12.04 LTS
and Ubuntu 14.04 LTS.
Original advisory details:
Stefan Buehler discovered that GnuTLS incorrectly verified the serial
length of OCSP responses. A remote attacker could possibly use this issue
to bypass certain certificate validation measures. This issue only applied
to Ubuntu 16.04 LTS. (CVE-2016-7444)
Shi Lei discovered that GnuTLS incorrectly handled certain warning alerts.
A remote attacker could possibly use this issue to cause GnuTLS to hang,
resulting in a denial of service. This issue has only been addressed in
Ubuntu 1
Ubuntu
GnuTLS vulnerabilities
vendor_ubuntu·2017-02-01·CVSS 7.5
CVE-2016-7444 [HIGH] GnuTLS vulnerabilities
Title: GnuTLS vulnerabilities
Summary: Several security issues were fixed in GnuTLS.
Stefan Buehler discovered that GnuTLS incorrectly verified the serial
length of OCSP responses. A remote attacker could possibly use this issue
to bypass certain certificate validation measures. This issue only applied
to Ubuntu 16.04 LTS. (CVE-2016-7444)
Shi Lei discovered that GnuTLS incorrectly handled certain warning alerts.
A remote attacker could possibly use this issue to cause GnuTLS to hang,
resulting in a denial of service. This issue has only been addressed in
Ubuntu 16.04 LTS and Ubuntu 16.10. (CVE-2016-8610)
It was discovered that GnuTLS incorrectly decoded X.509 certificates with a
Proxy Certificate Information extension. A remote attacker could use this
issue to cause GnuTLS to crash, re
Red Hat
gnutls: Heap read overflow in read-packet.c
vendor_redhat·2017-01-10·CVSS 9.8
CVE-2017-5337 [CRITICAL] CWE-122 gnutls: Heap read overflow in read-packet.c
gnutls: Heap read overflow in read-packet.c
Multiple heap-based buffer overflows in the read_attribute function in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allow remote attackers to have unspecified impact via a crafted OpenPGP certificate.
Package: gnutls (Red Hat Enterprise Linux 5) - Will not fix
Debian
CVE-2017-5337: gnutls28 - Multiple heap-based buffer overflows in the read_attribute function in GnuTLS be...
vendor_debian·2017·CVSS 9.8
CVE-2017-5337 [CRITICAL] CVE-2017-5337: gnutls28 - Multiple heap-based buffer overflows in the read_attribute function in GnuTLS be...
Multiple heap-based buffer overflows in the read_attribute function in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allow remote attackers to have unspecified impact via a crafted OpenPGP certificate.
Scope: local
bookworm: resolved (fixed in 3.5.8-1)
bullseye: resolved (fixed in 3.5.8-1)
forky: resolved (fixed in 3.5.8-1)
sid: resolved (fixed in 3.5.8-1)
trixie: resolved (fixed in 3.5.8-1)
GHSA
GHSA-c5c3-3h6m-3ghx: Multiple heap-based buffer overflows in the read_attribute function in GnuTLS before 3
ghsa_unreviewed·2022-05-14
CVE-2017-5337 [CRITICAL] CWE-119 GHSA-c5c3-3h6m-3ghx: Multiple heap-based buffer overflows in the read_attribute function in GnuTLS before 3
Multiple heap-based buffer overflows in the read_attribute function in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allow remote attackers to have unspecified impact via a crafted OpenPGP certificate.
OSV
CVE-2017-5337: Multiple heap-based buffer overflows in the read_attribute function in GnuTLS before 3
osv·2017-03-24·CVSS 9.8
CVE-2017-5337 [CRITICAL] CVE-2017-5337: Multiple heap-based buffer overflows in the read_attribute function in GnuTLS before 3
Multiple heap-based buffer overflows in the read_attribute function in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allow remote attackers to have unspecified impact via a crafted OpenPGP certificate.
OSV
gnutls26 vulnerability
osv·2017-03-20·CVSS 7.5
CVE-2016-8610 [HIGH] gnutls26 vulnerability
gnutls26 vulnerability
USN-3183-1 fixed CVE-2016-8610 in GnuTLS in Ubuntu 16.04 LTS and Ubuntu
16.10. This update provides the corresponding update for Ubuntu 12.04 LTS
and Ubuntu 14.04 LTS.
Original advisory details:
Stefan Buehler discovered that GnuTLS incorrectly verified the serial
length of OCSP responses. A remote attacker could possibly use this issue
to bypass certain certificate validation measures. This issue only applied
to Ubuntu 16.04 LTS. (CVE-2016-7444)
Shi Lei discovered that GnuTLS incorrectly handled certain warning alerts.
A remote attacker could possibly use this issue to cause GnuTLS to hang,
resulting in a denial of service. This issue has only been addressed in
Ubuntu 16.04 LTS and Ubuntu 16.10. (CVE-2016-8610)
It was discovered that GnuTLS incorrectly decoded
OSV
gnutls26, gnutls28 vulnerabilities
osv·2017-02-01·CVSS 7.5
CVE-2016-7444 [HIGH] gnutls26, gnutls28 vulnerabilities
gnutls26, gnutls28 vulnerabilities
Stefan Buehler discovered that GnuTLS incorrectly verified the serial
length of OCSP responses. A remote attacker could possibly use this issue
to bypass certain certificate validation measures. This issue only applied
to Ubuntu 16.04 LTS. (CVE-2016-7444)
Shi Lei discovered that GnuTLS incorrectly handled certain warning alerts.
A remote attacker could possibly use this issue to cause GnuTLS to hang,
resulting in a denial of service. This issue has only been addressed in
Ubuntu 16.04 LTS and Ubuntu 16.10. (CVE-2016-8610)
It was discovered that GnuTLS incorrectly decoded X.509 certificates with a
Proxy Certificate Information extension. A remote attacker could use this
issue to cause GnuTLS to crash, resulting in a denial of service, or
possibly execute
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-5335 CVE-2017-5336 CVE-2017-5337 gnutls30: various flaws [epel-6]
bugzilla·2017-01-10·CVSS 7.5
CVE-2017-5335 [HIGH] CVE-2017-5335 CVE-2017-5336 CVE-2017-5337 gnutls30: various flaws [epel-6]
CVE-2017-5335 CVE-2017-5336 CVE-2017-5337 gnutls30: various flaws [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-6.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Adding parent bug 1412236 (for CVE-2017-5336).
Bugzilla
CVE-2017-5334 CVE-2017-5335 CVE-2017-5336 CVE-2017-5337 gnutls: various flaws [fedora-all]
bugzilla·2017-01-10·CVSS 9.8
CVE-2017-5334 [CRITICAL] CVE-2017-5334 CVE-2017-5335 CVE-2017-5336 CVE-2017-5337 gnutls: various flaws [fedora-all]
CVE-2017-5334 CVE-2017-5335 CVE-2017-5336 CVE-2017-5337 gnutls: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple suppo
Bugzilla
CVE-2017-5337 gnutls: Heap read overflow in read-packet.c
bugzilla·2017-01-10·CVSS 9.8
CVE-2017-5337 [CRITICAL] CVE-2017-5337 gnutls: Heap read overflow in read-packet.c
CVE-2017-5337 gnutls: Heap read overflow in read-packet.c
A vulnerability was found in gnutls. A heap read overflow could occur while parsing maliciously crafted OpenPGP certificate.
References:
http://seclists.org/oss-sec/2017/q1/51
https://gnutls.org/security.html#GNUTLS-SA-2017-2
Upstream patch:
https://gitlab.com/gnutls/gnutls/commit/94fcf1645ea17223237aaf8d19132e004afddc1a
Discussion:
Created gnutls tracking bugs for this issue:
Affects: fedora-all [bug 1411838]
---
This was addressed in F25 with https://bodhi.fedoraproject.org/updates/FEDORA-2017-88f1664dd4
---
Created gnutls30 tracking bugs for this issue:
Affects: epel-6 [bug 1411845]
---
Reproducer at:
https://gitlab.com/gnutls/gnutls/commit/d949c6266ce64f5c2419f8c7cf4a196122fff9d7
---
and https://gitlab.com/gnutl
http://lists.opensuse.org/opensuse-security-announce/2017-02/msg00005.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0574.htmlhttp://www.openwall.com/lists/oss-security/2017/01/10/7http://www.openwall.com/lists/oss-security/2017/01/11/4http://www.securityfocus.com/bid/95372http://www.securitytracker.com/id/1037576https://access.redhat.com/errata/RHSA-2017:2292https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=338https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=346https://gitlab.com/gnutls/gnutls/commit/94fcf1645ea17223237aaf8d19132e004afddc1ahttps://gnutls.org/security.html#GNUTLS-SA-2017-2https://security.gentoo.org/glsa/201702-04http://lists.opensuse.org/opensuse-security-announce/2017-02/msg00005.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0574.htmlhttp://www.openwall.com/lists/oss-security/2017/01/10/7http://www.openwall.com/lists/oss-security/2017/01/11/4http://www.securityfocus.com/bid/95372http://www.securitytracker.com/id/1037576https://access.redhat.com/errata/RHSA-2017:2292https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=338https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=346https://gitlab.com/gnutls/gnutls/commit/94fcf1645ea17223237aaf8d19132e004afddc1ahttps://gnutls.org/security.html#GNUTLS-SA-2017-2https://security.gentoo.org/glsa/201702-04
2017-03-24
Published