Name
gnutls
Version
3.8.13
Type
library
Description
GNU Transport Layer Security Library
Licenses
GPL-3.0-or-later & LGPL-2.1-or-later
PURL
-
CPE
cpe:2.3:*:gnu:gnutls:3.8.13:*:*:*:*:*:*:*
Other Versions#
Patches#
#
Title
Author
Resolve
1
tests/pkcs11/trust-list-fault: fix issues in linking
Daiki Ueno <ueno@gnu.org>
2
gnutls: account for ARM_EABI
Joe Slater <jslater@windriver.com>
3
tests/mini-dtls-framents: link to gnulib
Alexander Sosedkin <asosedkin@redhat.com>
4
Creating .hmac file should be excuted in target environment,
Lei Maohui <leimaohui@fujitsu.com>
5
gnutls: add ptest support
Ravineet Singh <ravineet.a.singh@est.tech>
Vulnerabilities#
Name
Analysis
Description
Not Affected
A flaw was found in gnutls. A remote, unauthenticated attacker can exploit this vulnerability by sending a specially crafted ClientHello message with an invalid Pre-Shared Key (PSK) binder value during the TLS handshake. This can lead to a NULL pointer dereference, causing the server to crash and resulting in a remote Denial of Service (DoS) condition.
Not Affected
A heap-buffer-overflow (off-by-one) flaw was found in the GnuTLS software in the template parsing logic within the certtool utility. When it reads certain settings from a template file, it allows an attacker to cause an out-of-bounds (OOB) NULL pointer write, resulting in memory corruption and a denial-of-service (DoS) that could potentially crash the system.
Not Affected
A heap-buffer-overread vulnerability was found in GnuTLS in how it handles the Certificate Transparency (CT) Signed Certificate Timestamp (SCT) extension during X.509 certificate parsing. This flaw allows a malicious user to create a certificate containing a malformed SCT extension (OID 1.3.6.1.4.1.11129.2.4.2) that contains sensitive data. This issue leads to the exposure of confidential information when GnuTLS verifies certificates from certain websites when the certificate (SCT) is not checked correctly.