CVE-2017-7507
published 2017-06-16CVE-2017-7507: GnuTLS version 3.5.12 and earlier is vulnerable to a NULL pointer dereference while decoding a status response TLS extension with valid contents. This could…
PriorityP336high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
3.41%
87.5th percentile
GnuTLS version 3.5.12 and earlier is vulnerable to a NULL pointer dereference while decoding a status response TLS extension with valid contents. This could lead to a crash of the GnuTLS server application.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | gnutls28 | < gnutls28 3.5.8-6 (bookworm) | gnutls28 3.5.8-6 (bookworm) |
| gnu | gnutls | <= 3.5.12 | — |
| gnutls | gnutls | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-w59v-wh6q-qc58: GnuTLS version 3
ghsa_unreviewed·2022-05-14
CVE-2017-7507 [HIGH] CWE-476 GHSA-w59v-wh6q-qc58: GnuTLS version 3
GnuTLS version 3.5.12 and earlier is vulnerable to a NULL pointer dereference while decoding a status response TLS extension with valid contents. This could lead to a crash of the GnuTLS server application.
OSV
CVE-2017-7507: GnuTLS version 3
osv·2017-06-16·CVSS 7.5
CVE-2017-7507 [HIGH] CVE-2017-7507: GnuTLS version 3
GnuTLS version 3.5.12 and earlier is vulnerable to a NULL pointer dereference while decoding a status response TLS extension with valid contents. This could lead to a crash of the GnuTLS server application.
OSV
gnutls26, gnutls28 vulnerabilities
osv·2017-06-13·CVSS 7.5
CVE-2017-7507 [HIGH] gnutls26, gnutls28 vulnerabilities
gnutls26, gnutls28 vulnerabilities
Hubert Kario discovered that GnuTLS incorrectly handled decoding a status
response TLS extension. A remote attacker could possibly use this issue to
cause GnuTLS to crash, resulting in a denial of service. This issue only
applied to Ubuntu 16.04 LTS, Ubuntu 16.10 and Ubuntu 17.04. (CVE-2017-7507)
It was discovered that GnuTLS incorrectly handled decoding certain OpenPGP
certificates. A remote attacker could use this issue to cause GnuTLS to
crash, resulting in a denial of service, or possibly execute arbitrary
code. (CVE-2017-7869)
Ubuntu
GnuTLS vulnerabilities
vendor_ubuntu·2017-06-13·CVSS 7.5
CVE-2017-7507 [HIGH] GnuTLS vulnerabilities
Title: GnuTLS vulnerabilities
Summary: Several security issues were fixed in GnuTLS.
Hubert Kario discovered that GnuTLS incorrectly handled decoding a status
response TLS extension. A remote attacker could possibly use this issue to
cause GnuTLS to crash, resulting in a denial of service. This issue only
applied to Ubuntu 16.04 LTS, Ubuntu 16.10 and Ubuntu 17.04. (CVE-2017-7507)
It was discovered that GnuTLS incorrectly handled decoding certain OpenPGP
certificates. A remote attacker could use this issue to cause GnuTLS to
crash, resulting in a denial of service, or possibly execute arbitrary
code. (CVE-2017-7869)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
gnutls: Crash upon receiving well-formed status_request extension
vendor_redhat·2017-06-07·CVSS 7.5
CVE-2017-7507 [HIGH] gnutls: Crash upon receiving well-formed status_request extension
gnutls: Crash upon receiving well-formed status_request extension
GnuTLS version 3.5.12 and earlier is vulnerable to a NULL pointer dereference while decoding a status response TLS extension with valid contents. This could lead to a crash of the GnuTLS server application.
A null pointer dereference flaw was found in the way GnuTLS processed ClientHello messages with status_request extension. A remote attacker could use this flaw to cause an application compiled with GnuTLS to crash.
Package: gnutls (Red Hat Enterprise Linux 5) - Not affected
Package: gnutls (Red Hat Enterprise Linux 6) - Not affected
Package: mingw-virt-viewer (Red Hat Enterprise Virtualization 3) - Not affected
Debian
CVE-2017-7507: gnutls28 - GnuTLS version 3.5.12 and earlier is vulnerable to a NULL pointer dereference wh...
vendor_debian·2017·CVSS 7.5
CVE-2017-7507 [HIGH] CVE-2017-7507: gnutls28 - GnuTLS version 3.5.12 and earlier is vulnerable to a NULL pointer dereference wh...
GnuTLS version 3.5.12 and earlier is vulnerable to a NULL pointer dereference while decoding a status response TLS extension with valid contents. This could lead to a crash of the GnuTLS server application.
Scope: local
bookworm: resolved (fixed in 3.5.8-6)
bullseye: resolved (fixed in 3.5.8-6)
forky: resolved (fixed in 3.5.8-6)
sid: resolved (fixed in 3.5.8-6)
trixie: resolved (fixed in 3.5.8-6)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-7507 mingw-gnutls: gnutls: Crash upon receiving well-formed status_request extension [epel-7]
bugzilla·2017-06-08·CVSS 7.5
CVE-2017-7507 [HIGH] CVE-2017-7507 mingw-gnutls: gnutls: Crash upon receiving well-formed status_request extension [epel-7]
CVE-2017-7507 mingw-gnutls: gnutls: Crash upon receiving well-formed status_request extension [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the following
Bugzilla
CVE-2017-7507 gnutls30: gnutls: Crash upon receiving well-formed status_request extension [epel-6]
bugzilla·2017-06-08·CVSS 7.5
CVE-2017-7507 [HIGH] CVE-2017-7507 gnutls30: gnutls: Crash upon receiving well-formed status_request extension [epel-6]
CVE-2017-7507 gnutls30: gnutls: Crash upon receiving well-formed status_request extension [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-6.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the following temp
Bugzilla
CVE-2017-7507 mingw-gnutls: gnutls: Crash upon receiving well-formed status_request extension [fedora-all]
bugzilla·2017-06-08·CVSS 7.5
CVE-2017-7507 [HIGH] CVE-2017-7507 mingw-gnutls: gnutls: Crash upon receiving well-formed status_request extension [fedora-all]
CVE-2017-7507 mingw-gnutls: gnutls: Crash upon receiving well-formed status_request extension [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affect
Bugzilla
CVE-2017-7507 gnutls: Crash upon receiving well-formed status_request extension [fedora-all]
bugzilla·2017-06-08·CVSS 7.5
CVE-2017-7507 [HIGH] CVE-2017-7507 gnutls: Crash upon receiving well-formed status_request extension [fedora-all]
CVE-2017-7507 gnutls: Crash upon receiving well-formed status_request extension [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple sup
Bugzilla
CVE-2017-7507 gnutls: Crash upon receiving well-formed status_request extension
bugzilla·2017-05-23·CVSS 7.5
CVE-2017-7507 [HIGH] CVE-2017-7507 gnutls: Crash upon receiving well-formed status_request extension
CVE-2017-7507 gnutls: Crash upon receiving well-formed status_request extension
It was found that GnuTLS would crash when receiving a client hello message with status_request extension that has a non-empty responder_id_list.
Discussion:
Acknowledgments:
Name: Hubert Kario (Red Hat QE BaseOS Security team)
---
Created gnutls tracking bugs for this issue:
Affects: fedora-all [bug 1459795]
Created gnutls30 tracking bugs for this issue:
Affects: epel-6 [bug 1459797]
Created mingw-gnutls tracking bugs for this issue:
Affects: epel-7 [bug 1459796]
Affects: fedora-all [bug 1459798]
---
External References:
https://www.gnutls.org/security.html#GNUTLS-SA-2017-4
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2017:2292 https://acce
http://www.debian.org/security/2017/dsa-3884http://www.securityfocus.com/bid/99102https://access.redhat.com/errata/RHSA-2017:2292https://www.gnutls.org/security.html#GNUTLS-SA-2017-4http://www.debian.org/security/2017/dsa-3884http://www.securityfocus.com/bid/99102https://access.redhat.com/errata/RHSA-2017:2292https://www.gnutls.org/security.html#GNUTLS-SA-2017-4
2017-06-16
Published