Vulnerability CVE-2014-8564


Published: 2014-11-13

Description:
The _gnutls_ecc_ansi_x963_export function in gnutls_ecc.c in GnuTLS 3.x before 3.1.28, 3.2.x before 3.2.20, and 3.3.x before 3.3.10 allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted (1) Elliptic Curve Cryptography (ECC) certificate or (2) certificate signing requests (CSR), related to generating key IDs.

Type:

CWE-310

(Cryptographic Issues)

CVSS2 => (AV:N/AC:L/Au:N/C:N/I:N/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
5/10
2.9/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
None
None
Partial
Affected software
Redhat -> Enterprise linux desktop 
Redhat -> Enterprise linux hpc node 
Redhat -> Enterprise linux server 
Redhat -> Enterprise linux workstation 
Opensuse -> Opensuse 
Novell -> Opensuse 
GNU -> Gnutls 
Canonical -> Ubuntu linux 

 References:
http://lists.opensuse.org/opensuse-updates/2014-11/msg00084.html
http://rhn.redhat.com/errata/RHSA-2014-1846.html
http://www.ubuntu.com/usn/USN-2403-1
https://bugzilla.redhat.com/show_bug.cgi?id=1161443

Copyright 2024, cxsecurity.com

 

Back to Top