CVE-2012-1573

medium
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

gnutls_cipher.c in libgnutls in GnuTLS before 2.12.17 and 3.x before 3.0.15 does not properly handle data encrypted with a block cipher, which allows remote attackers to cause a denial of service (heap memory corruption and application crash) via a crafted record, as demonstrated by a crafted GenericBlockCipher structure.

References

http://archives.neohapsis.com/archives/bugtraq/2012-03/0099.html

http://article.gmane.org/gmane.comp.encryption.gpg.gnutls.devel/5910

http://article.gmane.org/gmane.comp.encryption.gpg.gnutls.devel/5912

http://blog.mudynamics.com/2012/03/20/gnutls-and-libtasn1-vulns/

http://git.savannah.gnu.org/gitweb/?p=gnutls.git;a=commit;h=422214868061370aeeb0ac9cd0f021a5c350a57d

http://git.savannah.gnu.org/gitweb/?p=gnutls.git;a=commit;h=b495740f2ff66550ca9395b3fda3ea32c3acb185

http://lists.fedoraproject.org/pipermail/package-announce/2012-April/077071.html

http://lists.fedoraproject.org/pipermail/package-announce/2012-March/076496.html

http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00001.html

http://osvdb.org/80259

http://rhn.redhat.com/errata/RHSA-2012-0429.html

http://rhn.redhat.com/errata/RHSA-2012-0488.html

http://rhn.redhat.com/errata/RHSA-2012-0531.html

http://secunia.com/advisories/48488

http://secunia.com/advisories/48511

http://secunia.com/advisories/48596

http://secunia.com/advisories/48712

http://secunia.com/advisories/57260

http://www.debian.org/security/2012/dsa-2441

http://www.gnu.org/software/gnutls/security.html

http://www.mandriva.com/security/advisories?name=MDVSA-2012:040

http://www.openwall.com/lists/oss-security/2012/03/21/4

http://www.openwall.com/lists/oss-security/2012/03/21/5

http://www.securityfocus.com/bid/52667

http://www.securitytracker.com/id?1026828

http://www.ubuntu.com/usn/USN-1418-1

https://bugzilla.redhat.com/show_bug.cgi?id=805432

Details

Source: MITRE

Published: 2012-03-26

Updated: 2018-01-18

Type: CWE-310

Risk Information

CVSS v2

Base Score: 5

Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Impact Score: 2.9

Exploitability Score: 10

Severity: MEDIUM

Vulnerable Software

Configuration 1

OR

cpe:2.3:a:gnu:gnutls:2.0.0:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:2.0.1:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:2.0.2:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:2.0.3:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:2.0.4:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:2.1.0:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:2.1.1:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:2.1.2:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:2.1.3:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:2.1.4:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:2.1.5:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:2.1.6:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:2.1.7:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:2.1.8:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:2.2.0:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:2.2.1:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:2.2.2:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:2.2.3:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:2.2.4:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:2.2.5:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:2.3.0:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:2.3.1:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:2.3.2:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:2.3.3:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:2.3.4:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:2.3.5:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:2.3.6:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:2.3.7:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:2.3.8:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:2.3.9:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:2.3.10:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:2.3.11:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:2.4.0:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:2.4.1:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:2.4.2:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:2.4.3:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:2.5.0:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:2.6.0:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:2.6.1:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:2.6.2:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:2.6.3:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:2.6.4:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:2.6.5:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:2.6.6:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:2.7.4:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:2.8.0:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:2.8.1:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:2.8.2:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:2.8.3:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:2.8.4:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:2.8.5:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:2.8.6:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:2.10.0:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:2.10.1:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:2.10.2:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:2.10.3:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:2.10.4:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:2.10.5:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:2.12.0:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:2.12.1:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:2.12.2:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:2.12.3:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:2.12.4:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:2.12.5:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:2.12.6:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:2.12.6.1:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:2.12.7:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:2.12.8:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:2.12.9:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:2.12.10:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:2.12.11:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:2.12.12:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:2.12.13:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:2.12.14:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:2.12.15:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:*:*:*:*:*:*:*:* versions up to 2.12.16 (inclusive)

Configuration 2

OR

cpe:2.3:a:gnu:gnutls:3.0:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:3.0.0:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:3.0.1:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:3.0.2:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:3.0.3:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:3.0.4:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:3.0.5:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:3.0.6:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:3.0.7:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:3.0.8:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:3.0.9:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:3.0.10:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:3.0.11:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:3.0.12:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:3.0.13:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:3.0.14:*:*:*:*:*:*:*

Tenable Plugins

View all (25 total)

IDNameProductFamilySeverity
89038VMware ESX / ESXi Third-Party Libraries Multiple Vulnerabilities (VMSA-2012-0013) (remote check)NessusMisc.
high
80629Oracle Solaris Third-Party Patch Update : gnutls (cve_2012_1573_denial_of)NessusSolaris Local Security Checks
medium
79286RHEL 5 : rhev-hypervisor5 (RHSA-2012:0488)NessusRed Hat Local Security Checks
medium
78922RHEL 6 : rhev-hypervisor6 (RHSA-2012:0531)NessusRed Hat Local Security Checks
high
74627openSUSE Security Update : gnutls (openSUSE-SU-2012:0620-1)NessusSuSE Local Security Checks
high
70439Slackware 12.1 / 12.2 / 13.0 / 13.1 / 13.37 : gnutls (SSA:2013-287-03)NessusSlackware Local Security Checks
medium
69666Amazon Linux AMI : gnutls (ALAS-2012-59)NessusAmazon Linux Local Security Checks
medium
68504Oracle Linux 6 : gnutls (ELSA-2012-0429)NessusOracle Linux Local Security Checks
medium
68503Oracle Linux 5 : gnutls (ELSA-2012-0428)NessusOracle Linux Local Security Checks
medium
64152SuSE 11.1 Security Update : GnuTLS (SAT Patch Number 6448)NessusSuSE Local Security Checks
medium
61747VMSA-2012-0013 : VMware vSphere and vCOps updates to third-party librariesNessusVMware ESX Local Security Checks
critical
61291Scientific Linux Security Update : gnutls on SL6.x i386/x86_64 (20120327)NessusScientific Linux Local Security Checks
medium
61290Scientific Linux Security Update : gnutls on SL5.x i386/x86_64 (20120327)NessusScientific Linux Local Security Checks
medium
59829SuSE 10 Security Update : GnuTLS (ZYPP Patch Number 8066)NessusSuSE Local Security Checks
medium
59671GLSA-201206-18 : GnuTLS: Multiple vulnerabilitiesNessusGentoo Local Security Checks
high
58668Fedora 15 : gnutls-2.10.5-3.fc15 (2012-4569)NessusFedora Local Security Checks
medium
58618Ubuntu 8.04 LTS / 10.04 LTS / 10.10 / 11.04 / 11.10 : gnutls13, gnutls26 vulnerabilities (USN-1418-1)NessusUbuntu Local Security Checks
medium
58519CentOS 6 : gnutls (CESA-2012:0429)NessusCentOS Local Security Checks
medium
58510RHEL 6 : gnutls (RHSA-2012:0429)NessusRed Hat Local Security Checks
medium
58509RHEL 5 : gnutls (RHSA-2012:0428)NessusRed Hat Local Security Checks
medium
58505Mandriva Linux Security Advisory : gnutls (MDVSA-2012:040)NessusMandriva Local Security Checks
medium
58504CentOS 5 : gnutls (CESA-2012:0428)NessusCentOS Local Security Checks
medium
58469Fedora 16 : gnutls-2.12.14-2.fc16 (2012-4578)NessusFedora Local Security Checks
medium
58460Debian DSA-2441-1 : gnutls26 - missing bounds checkNessusDebian Local Security Checks
medium
58423FreeBSD : gnutls -- possible overflow/Denial of service vulnerabilities (aecee357-739e-11e1-a883-001cc0a36e12)NessusFreeBSD Local Security Checks
medium