5
CVSSv2

CVE-2006-7239

Published: 24/05/2010 Updated: 13/02/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The _gnutls_x509_oid2mac_algorithm function in lib/gnutls_algorithms.c in GnuTLS prior to 1.4.2 allows remote malicious users to cause a denial of service (crash) via a crafted X.509 certificate that uses a hash algorithm that is not supported by GnuTLS, which triggers a NULL pointer dereference.

Vulnerable Product Search on Vulmon Subscribe to Product

gnu gnutls 1.2.8

gnu gnutls 1.1.14

gnu gnutls 1.2.11

gnu gnutls 1.1.21

gnu gnutls 1.0.20

gnu gnutls 1.2.5

gnu gnutls 1.0.17

gnu gnutls 1.2.4

gnu gnutls 1.3.1

gnu gnutls 1.0.24

gnu gnutls 1.0.21

gnu gnutls 1.0.16

gnu gnutls 1.1.20

gnu gnutls 1.2.10

gnu gnutls 1.1.22

gnu gnutls 1.4.0

gnu gnutls 1.3.4

gnu gnutls 1.0.19

gnu gnutls 1.2.1

gnu gnutls 1.1.19

gnu gnutls 1.1.18

gnu gnutls

gnu gnutls 1.1.13

gnu gnutls 1.2.8.1a1

gnu gnutls 1.2.2

gnu gnutls 1.2.0

gnu gnutls 1.0.18

gnu gnutls 1.2.7

gnu gnutls 1.3.2

gnu gnutls 1.0.25

gnu gnutls 1.1.15

gnu gnutls 1.0.23

gnu gnutls 1.3.0

gnu gnutls 1.3.5

gnu gnutls 1.1.23

gnu gnutls 1.2.3

gnu gnutls 1.2.6

gnu gnutls 1.2.9

gnu gnutls 1.1.16

gnu gnutls 1.0.22

gnu gnutls 1.1.17

gnu gnutls 1.3.3

Vendor Advisories

Under certain circumstances, an attacker might be able to crash GnuTLS ...