CVE-2017-7869

CWE-787Out-of-bounds Write12 documents8 sources
Severity
7.5HIGH
EPSS
0.7%
top 27.93%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 14
Latest updateMay 14

Description

GnuTLS before 2017-02-20 has an out-of-bounds write caused by an integer overflow and heap-based buffer overflow related to the cdk_pkt_read function in opencdk/read-packet.c. This issue (which is a subset of the vendor's GNUTLS-SA-2017-3 report) is fixed in 3.5.10.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

Debiangnutls28< 3.5.8-4+3
NVDgnu/gnutls3.5.9

Patches

🔴Vulnerability Details

4
GHSA
GHSA-8cj2-6v9c-5x8f: GnuTLS before 2017-02-20 has an out-of-bounds write caused by an integer overflow and heap-based buffer overflow related to the cdk_pkt_read function2022-05-14
OSV
gnutls26, gnutls28 vulnerabilities2017-06-13
OSV
CVE-2017-7869: GnuTLS before 2017-02-20 has an out-of-bounds write caused by an integer overflow and heap-based buffer overflow related to the cdk_pkt_read function2017-04-14
CVEList
CVE-2017-7869: GnuTLS before 2017-02-20 has an out-of-bounds write caused by an integer overflow and heap-based buffer overflow related to the cdk_pkt_read function2017-04-14

📋Vendor Advisories

3
Ubuntu
GnuTLS vulnerabilities2017-06-13
Red Hat
gnutls: Out-of-bounds write related to the cdk_pkt_read function (GNUTLS-SA-2017-3)2017-04-14
Debian
CVE-2017-7869: gnutls28 - GnuTLS before 2017-02-20 has an out-of-bounds write caused by an integer overflo...2017

💬Community

4
Bugzilla
CVE-2017-7869 mingw-gnutls: gnutls: Out-of-bounds write related to the cdk_pkt_read function (GNUTLS-SA-2017-3) [fedora-all]2017-04-19
Bugzilla
CVE-2017-7869 gnutls30: gnutls: Out-of-bounds write related to the cdk_pkt_read function (GNUTLS-SA-2017-3) [epel-6]2017-04-19
Bugzilla
CVE-2017-7869 mingw-gnutls: gnutls: Out-of-bounds write related to the cdk_pkt_read function (GNUTLS-SA-2017-3) [epel-7]2017-04-19
Bugzilla
CVE-2017-7869 gnutls: Out-of-bounds write related to the cdk_pkt_read function (GNUTLS-SA-2017-3)2017-04-18
CVE-2017-7869 (HIGH CVSS 7.5) | GnuTLS before 2017-02-20 has an out | cvebase.io