Memory corruption in Gnu - CVE-2017-5335
Published: August 2, 2017
Vulnerability identifier: #VU7657
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-5335
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote unauthenticated attacker to cause DoS condition on the target system.
The weakness exists due to insufficient error checking in the stream-reading functions. A remote attacker can send a specially crafted OpenPGP certificate, trigger memory corruption and cause the application to crash.
Successful exploitation of the vulnerability results in denial of service.
The weakness exists due to insufficient error checking in the stream-reading functions. A remote attacker can send a specially crafted OpenPGP certificate, trigger memory corruption and cause the application to crash.
Successful exploitation of the vulnerability results in denial of service.
Affected software
Gnu
Gentoo Linux
Amazon Linux AMI
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Fedora
SUSE Linux
Ubuntu
Slackware Linux
Opensuse
gnutls (Red Hat package)
gnutls
gnutls30
Gentoo Linux
Amazon Linux AMI
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Fedora
SUSE Linux
Ubuntu
Slackware Linux
Opensuse
gnutls (Red Hat package)
gnutls
gnutls30
How to mitigate CVE-2017-5335
Update to version 3.3.26 or 3.5.8.
gnutls (Red Hat package) - update to 2.12.23-21.el6
gnutls - update to 3.4.17-2.fc24
gnutls30 - update to 3.5.8-1.el6
gnutls - update to 3.4.17-2.fc24
gnutls30 - update to 3.5.8-1.el6
External References
Related Security Bulletins
- Denial of service in GnuTLS
- Red Hat update for GnuTLS
- Gentoo update for GnuTLS
- Ubuntu update for GnuTLS
- Ubuntu update for GnuTLS
- Slackware Linux update for gnutls
- Amazon Linux AMI update for gnutls
- SUSE Linux update for gnutls
- OpenSUSE Linux update for gnutls
- SUSE Linux update for gnutls
- Fedora EPEL 6 update for gnutls30
- Fedora 24 update for gnutls
- Red Hat Enterprise Linux 6 update for gnutls