5
CVSSv2

CVE-2013-4487

Published: 20/11/2013 Updated: 30/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Off-by-one error in the dane_raw_tlsa in the DANE library (libdane) in GnuTLS 3.1.x prior to 3.1.16 and 3.2.x prior to 3.2.6 allows remote servers to cause a denial of service (memory corruption) via a response with more than four DANE entries. NOTE: this issue is due to an incomplete fix for CVE-2013-4466.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

gnu gnutls 3.2.4

gnu gnutls 3.2.5

gnu gnutls 3.2.1

gnu gnutls 3.2.3

gnu gnutls 3.2.0

gnu gnutls 3.2.2

gnu gnutls 3.1.13

gnu gnutls 3.1.14

gnu gnutls 3.1.15

gnu gnutls 3.1.2

gnu gnutls 3.1.0

gnu gnutls 3.1.7

gnu gnutls 3.1.8

gnu gnutls 3.1.9

gnu gnutls 3.1.1

gnu gnutls 3.1.11

gnu gnutls 3.1.4

gnu gnutls 3.1.6

gnu gnutls 3.1.10

gnu gnutls 3.1.12

gnu gnutls 3.1.3

gnu gnutls 3.1.5

opensuse opensuse 13.1