Boletines de Vulnerabilidades

DSA-3334 gnutls28 - security update


Información sobre el sistema

   
Software afectado Debian

Descripción

Kurt Roeckx discovered that decoding a specific certificate with verylong DistinguishedName (DN) entries leads to double free. A remoteattacker can take advantage of this flaw by creating a specially craftedcertificate that, when processed by an application compiled againstGnuTLS, could cause the application to crash resulting in a denial ofservice.

More info:

https://www.debian.org/security/2015/dsa-3334

Identificadores estándar

Propiedad Valor
CVE DSA-3334.

Histórico de versiones

Versión Comentario Fecha
1.0 Advisory issued 2015-08-14

Miembros de

Ministerio de Defensa
CNI
CCN
CCN-CERT