4.3
CVSSv2

CVE-2011-4128

Published: 08/12/2011 Updated: 07/11/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

Buffer overflow in the gnutls_session_get_data function in lib/gnutls_session.c in GnuTLS 2.12.x prior to 2.12.14 and 3.x prior to 3.0.7, when used on a client that performs nonstandard session resumption, allows remote TLS servers to cause a denial of service (application crash) via a large SessionTicket.

Vulnerable Product Search on Vulmon Subscribe to Product

gnu gnutls 2.12.2

gnu gnutls 2.12.7

gnu gnutls 2.12.5

gnu gnutls 2.12.8

gnu gnutls 2.12.6.1

gnu gnutls 2.12.0

gnu gnutls 2.12.10

gnu gnutls 2.12.6

gnu gnutls 2.12.9

gnu gnutls 2.12.13

gnu gnutls 2.12.12

gnu gnutls 2.12.3

gnu gnutls 2.12.4

gnu gnutls 2.12.11

gnu gnutls 2.12.1

gnu gnutls 3.0.3

gnu gnutls 3.0.6

gnu gnutls 3.0.0

gnu gnutls 3.0.2

gnu gnutls 3.0.5

gnu gnutls 3.0.1

gnu gnutls 3.0.4

Vendor Advisories

The GnuTLS library could be made to crash under certain conditions ...
Synopsis Important: gnutls security update Type/Severity Security Advisory: Important Topic Updated gnutls packages that fix two security issues are now available forRed Hat Enterprise Linux 6The Red Hat Security Response Team has rated this update as havingimportant security impact Common Vulnerability S ...
Synopsis Important: gnutls security update Type/Severity Security Advisory: Important Topic Updated gnutls packages that fix three security issues are now availablefor Red Hat Enterprise Linux 5The Red Hat Security Response Team has rated this update as havingimportant security impact Common Vulnerability ...
A flaw was found in the way GnuTLS decrypted malformed TLS records This could cause a TLS/SSL client or server to crash when processing a specially-crafted TLS record from a remote TLS/SSL connection peer (CVE-2012-1573) A boundary error was found in the gnutls_session_get_data() function A malicious TLS/SSL server could use this flaw to crash a ...