2014-11-13 22:32:13 2018-10-30 17:27:35

The _gnutls_ecc_ansi_x963_export function in gnutls_ecc.c in GnuTLS 3.x before 3.1.28, 3.2.x before 3.2.20, and 3.3.x before 3.3.10 allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted (1) Elliptic Curve Cryptography (ECC) certificate or (2) certificate signing requests (CSR), related to generating key IDs.

Vector

NETWORK

Complexity

LOW

Authentication

NONE

Confidentiality

NONE

Integrity

NONE

Availability

PARTIAL
Gnu Gnutls 3.3.9 (not an official CPE) Gnu Gnutls 3.3.8 (not an official CPE) Gnu Gnutls 3.3.7 (not an official CPE) Gnu Gnutls 3.3.6 (not an official CPE) Gnu Gnutls 3.3.5 (not an official CPE) GNU GnuTLS 3.3.4 GNU GnuTLS 3.3.3 GNU GnuTLS 3.3.2 GNU GnuTLS 3.3.1 GNU GnuTLS 3.3.0 pre0 GNU GnuTLS 3.3.0 Gnu Gnutls 3.2.19 (not an official CPE) Gnu Gnutls 3.2.18 (not an official CPE) Gnu Gnutls 3.2.17 (not an official CPE) Gnu Gnutls 3.2.16 (not an official CPE) GNU GnuTLS 3.2.15 GNU GnuTLS 3.2.14 GNU GnuTLS 3.2.13 GNU GnuTLS 3.2.12.1 GNU GnuTLS 3.2.12 GNU GnuTLS 3.2.11 GNU GnuTLS 3.2.10 GNU GnuTLS 3.2.9 GNU GnuTLS 3.2.8.1 GNU GnuTLS 3.2.8 GNU GnuTLS 3.2.7 GNU GnuTLS 3.2.6 GNU GnuTLS 3.2.5 GNU GnuTLS 3.2.4 GNU GnuTLS 3.2.3 GNU GnuTLS 3.2.2 GNU GnuTLS 3.2.1 GNU GnuTLS 3.2.0 Gnu Gnutls 3.1.27 (not an official CPE) Gnu Gnutls 3.1.26 (not an official CPE) GNU GnuTLS 3.1.25 GNU GnuTLS 3.1.24 GNU GnuTLS 3.1.23 GNU GnuTLS 3.1.22 GNU GnuTLS 3.1.21 GNU GnuTLS 3.1.20 GNU GnuTLS 3.1.19 GNU GnuTLS 3.1.18 GNU GnuTLS 3.1.17 GNU GnuTLS 3.1.16 GNU GnuTLS 3.1.15 GNU GnuTLS 3.1.14 GNU GnuTLS 3.1.13 GNU GnuTLS 3.1.12 GNU GnuTLS 3.1.11 GNU GnuTLS 3.1.10 GNU GnuTLS 3.1.9 GNU GnuTLS 3.1.8 GNU GnuTLS 3.1.7 GNU GnuTLS 3.1.6 GNU GnuTLS 3.1.5 GNU GnuTLS 3.1.4 GNU GnuTLS 3.1.3 GNU GnuTLS 3.1.2 GNU GnuTLS 3.1.1 GNU GnuTLS 3.1.0 GNU GnuTLS 3.0.28 GNU GnuTLS 3.0.27 GNU GnuTLS 3.0.26 GNU GnuTLS 3.0.25 GNU GnuTLS 3.0.24 GNU GnuTLS 3.0.23 GNU GnuTLS 3.0.22 GNU GnuTLS 3.0.21 GNU GnuTLS 3.0.20 GNU GnuTLS 3.0.19 GNU GnuTLS 3.0.18 GNU GnuTLS 3.0.17 GNU GnuTLS 3.0.16 GNU GnuTLS 3.0.15 GNU GnuTLS 3.0.14 GNU GnuTLS 3.0.13 GNU GnuTLS 3.0.12 GNU GnuTLS 3.0.11 GNU GnuTLS 3.0.10 GNU GnuTLS 3.0.9 GNU GnuTLS 3.0.8 GNU GnuTLS 3.0.7 GNU GnuTLS 3.0.6 GNU GnuTLS 3.0.5 GNU GnuTLS 3.0.4 GNU GnuTLS 3.0.3 GNU GnuTLS 3.0.2 GNU GnuTLS 3.0.1 GNU GnuTLS 3.0.0 GNU TLS 3.0