5
CVSSv2

CVE-2013-4466

Published: 20/11/2013 Updated: 21/11/2013
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Buffer overflow in the dane_query_tlsa function in the DANE library (libdane) in GnuTLS 3.1.x prior to 3.1.15 and 3.2.x prior to 3.2.5 allows remote servers to cause a denial of service (memory corruption) via a response with more than four DANE entries.

Vulnerable Product Search on Vulmon Subscribe to Product

gnu gnutls 3.1.2

gnu gnutls 3.1.3

gnu gnutls 3.1.4

gnu gnutls 3.1.5

gnu gnutls 3.2.0

gnu gnutls 3.2.2

gnu gnutls 3.1.13

gnu gnutls 3.1.0

gnu gnutls 3.1.7

gnu gnutls 3.2.1

gnu gnutls 3.2.3

gnu gnutls 3.1.12

gnu gnutls 3.1.14

gnu gnutls 3.1.1

gnu gnutls 3.1.6

gnu gnutls 3.1.8

gnu gnutls 3.2.4

gnu gnutls 3.1.9

gnu gnutls 3.1.10

gnu gnutls 3.1.11

Vendor Advisories

Buffer overflow in the dane_query_tlsa function in the DANE library (libdane) in GnuTLS 31x before 3115 and 32x before 325 allows remote servers to cause a denial of service (memory corruption) via a response with more than four DANE entries ...