CVE-2011-4128

medium
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

Buffer overflow in the gnutls_session_get_data function in lib/gnutls_session.c in GnuTLS 2.12.x before 2.12.14 and 3.x before 3.0.7, when used on a client that performs nonstandard session resumption, allows remote TLS servers to cause a denial of service (application crash) via a large SessionTicket.

References

http://article.gmane.org/gmane.comp.encryption.gpg.gnutls.devel/5596

http://git.savannah.gnu.org/gitweb/?p=gnutls.git;a=commitdiff;h=190cef6eed37d0e73a73c1e205eb31d45ab60a3c

http://git.savannah.gnu.org/gitweb/?p=gnutls.git;a=commitdiff;h=e82ef4545e9e98cbcb032f55d7c750b81e3a0450

http://lists.fedoraproject.org/pipermail/package-announce/2012-April/077071.html

http://openwall.com/lists/oss-security/2011/11/09/2

http://openwall.com/lists/oss-security/2011/11/09/4

http://rhn.redhat.com/errata/RHSA-2012-0429.html

http://rhn.redhat.com/errata/RHSA-2012-0488.html

http://rhn.redhat.com/errata/RHSA-2012-0531.html

http://secunia.com/advisories/48596

http://secunia.com/advisories/48712

http://www.gnu.org/software/gnutls/security.html

http://www.mandriva.com/security/advisories?name=MDVSA-2012:045

http://www.ubuntu.com/usn/USN-1418-1

https://bugzilla.redhat.com/show_bug.cgi?id=752308

Details

Source: MITRE

Published: 2011-12-08

Updated: 2017-12-29

Type: CWE-119

Risk Information

CVSS v2

Base Score: 4.3

Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Impact Score: 2.9

Exploitability Score: 8.6

Severity: MEDIUM

Tenable Plugins

View all (22 total)

IDNameProductFamilySeverity
89038VMware ESX / ESXi Third-Party Libraries Multiple Vulnerabilities (VMSA-2012-0013) (remote check)NessusMisc.
high
80628Oracle Solaris Third-Party Patch Update : gnutls (cve_2011_4128_buffer_overflow)NessusSolaris Local Security Checks
medium
79286RHEL 5 : rhev-hypervisor5 (RHSA-2012:0488)NessusRed Hat Local Security Checks
medium
78922RHEL 6 : rhev-hypervisor6 (RHSA-2012:0531)NessusRed Hat Local Security Checks
high
75855openSUSE Security Update : gnutls (openSUSE-SU-2012:0215-1)NessusSuSE Local Security Checks
medium
70439Slackware 12.1 / 12.2 / 13.0 / 13.1 / 13.37 : gnutls (SSA:2013-287-03)NessusSlackware Local Security Checks
medium
69666Amazon Linux AMI : gnutls (ALAS-2012-59)NessusAmazon Linux Local Security Checks
medium
68504Oracle Linux 6 : gnutls (ELSA-2012-0429)NessusOracle Linux Local Security Checks
medium
68503Oracle Linux 5 : gnutls (ELSA-2012-0428)NessusOracle Linux Local Security Checks
medium
61747VMSA-2012-0013 : VMware vSphere and vCOps updates to third-party librariesNessusVMware ESX Local Security Checks
critical
61291Scientific Linux Security Update : gnutls on SL6.x i386/x86_64 (20120327)NessusScientific Linux Local Security Checks
medium
61290Scientific Linux Security Update : gnutls on SL5.x i386/x86_64 (20120327)NessusScientific Linux Local Security Checks
medium
59671GLSA-201206-18 : GnuTLS: Multiple vulnerabilitiesNessusGentoo Local Security Checks
high
58668Fedora 15 : gnutls-2.10.5-3.fc15 (2012-4569)NessusFedora Local Security Checks
medium
58618Ubuntu 8.04 LTS / 10.04 LTS / 10.10 / 11.04 / 11.10 : gnutls13, gnutls26 vulnerabilities (USN-1418-1)NessusUbuntu Local Security Checks
medium
58557Mandriva Linux Security Advisory : gnutls (MDVSA-2012:045)NessusMandriva Local Security Checks
medium
58519CentOS 6 : gnutls (CESA-2012:0429)NessusCentOS Local Security Checks
medium
58510RHEL 6 : gnutls (RHSA-2012:0429)NessusRed Hat Local Security Checks
medium
58509RHEL 5 : gnutls (RHSA-2012:0428)NessusRed Hat Local Security Checks
medium
58504CentOS 5 : gnutls (CESA-2012:0428)NessusCentOS Local Security Checks
medium
57696SuSE 11.1 Security Update : GnuTLS (SAT Patch Number 5684)NessusSuSE Local Security Checks
medium
56763FreeBSD : gnutls -- client session resumption vulnerability (bdec8dc2-0b3b-11e1-b722-001cc0476564)NessusFreeBSD Local Security Checks
medium