Null pointer dereference in Gnu - CVE-2017-7507

 

Null pointer dereference in Gnu - CVE-2017-7507

Published: July 12, 2017


Vulnerability identifier: #VU7481
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-7507
CWE-ID: CWE-476
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause DoS condition on the target system.

The weakness exists due to NULL pointer dereference while decoding a status response TLS extension with valid contents. A remote attacker can send specially crafted status_request extension in a ClientHello message to cause the GnuTLS server application to crash.

Successful exploitation of the vulnerability results in denial of service.

Affected software

Gnu
Arch Linux
Gentoo Linux
Debian Linux
Fedora
Red Hat Enterprise Linux Server
Ubuntu
gnutls (Alpine package)
gnutls
mingw-gnutls
gnutls30

How to mitigate CVE-2017-7507

Update to version 3.5.13 or later.

gnutls (Alpine package) - addressed in versions 3.4.17-r0, 3.4.17-r1
gnutls - addressed in versions 3.5.13-1.fc25, 3.5.13-1.fc26
mingw-gnutls - update to 3.5.13-1.fc26
gnutls30 - addressed in versions 3.5.18-1.el6, 3.5.19-1.el6

External References

Related Security Bulletins