CVE-2014-3466

medium
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

Buffer overflow in the read_server_hello function in lib/gnutls_handshake.c in GnuTLS before 3.1.25, 3.2.x before 3.2.15, and 3.3.x before 3.3.4 allows remote servers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a long session id in a ServerHello message.

References

http://linux.oracle.com/errata/ELSA-2014-0594.html

http://linux.oracle.com/errata/ELSA-2014-0595.html

http://lists.opensuse.org/opensuse-security-announce/2014-06/msg00002.html

http://lists.opensuse.org/opensuse-security-announce/2014-06/msg00007.html

http://lists.opensuse.org/opensuse-security-announce/2014-06/msg00010.html

http://lists.opensuse.org/opensuse-security-announce/2014-06/msg00015.html

http://radare.today/technical-analysis-of-the-gnutls-hello-vulnerability/

http://rhn.redhat.com/errata/RHSA-2014-0594.html

http://rhn.redhat.com/errata/RHSA-2014-0595.html

http://rhn.redhat.com/errata/RHSA-2014-0684.html

http://rhn.redhat.com/errata/RHSA-2014-0815.html

http://secunia.com/advisories/58340

http://secunia.com/advisories/58598

http://secunia.com/advisories/58601

http://secunia.com/advisories/58642

http://secunia.com/advisories/59016

http://secunia.com/advisories/59021

http://secunia.com/advisories/59057

http://secunia.com/advisories/59086

http://secunia.com/advisories/59408

http://secunia.com/advisories/59838

http://secunia.com/advisories/60384

http://www.debian.org/security/2014/dsa-2944

http://www.gnutls.org/security.html

http://www.novell.com/support/kb/doc.php?id=7015302

http://www.novell.com/support/kb/doc.php?id=7015303

http://www.securityfocus.com/bid/67741

http://www.securitytracker.com/id/1030314

http://www.ubuntu.com/usn/USN-2229-1

http://www-01.ibm.com/support/docview.wss?uid=swg21678776

http://www-947.ibm.com/support/entry/portal/docdisplay?lndocid=MIGR-5096155

https://bugzilla.redhat.com/show_bug.cgi?id=1101932

https://www.gitorious.org/gnutls/gnutls/commit/688ea6428a432c39203d00acd1af0e7684e5ddfd

Details

Source: MITRE

Published: 2014-06-03

Updated: 2017-12-29

Type: CWE-119

Risk Information

CVSS v2

Base Score: 6.8

Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Impact Score: 6.4

Exploitability Score: 8.6

Severity: MEDIUM

Vulnerable Software

Configuration 1

OR

cpe:2.3:a:gnu:gnutls:3.3.0:-:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:3.3.0:pre0:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:3.3.1:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:3.3.2:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:3.3.3:*:*:*:*:*:*:*

Configuration 2

OR

cpe:2.3:a:gnu:gnutls:3.1.0:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:3.1.1:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:3.1.2:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:3.1.3:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:3.1.4:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:3.1.5:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:3.1.6:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:3.1.7:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:3.1.8:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:3.1.9:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:3.1.10:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:3.1.11:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:3.1.12:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:3.1.13:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:3.1.14:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:3.1.15:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:3.1.16:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:3.1.17:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:3.1.18:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:3.1.19:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:3.1.20:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:3.1.21:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:3.1.22:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:3.1.23:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:*:*:*:*:*:*:*:* versions up to 3.1.24 (inclusive)

Configuration 3

OR

cpe:2.3:a:gnu:gnutls:3.2.0:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:3.2.1:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:3.2.2:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:3.2.3:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:3.2.4:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:3.2.5:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:3.2.6:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:3.2.7:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:3.2.8:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:3.2.8.1:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:3.2.9:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:3.2.10:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:3.2.11:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:3.2.12:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:3.2.12.1:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:3.2.13:*:*:*:*:*:*:*

cpe:2.3:a:gnu:gnutls:3.2.14:*:*:*:*:*:*:*

Tenable Plugins

View all (29 total)

IDNameProductFamilySeverity
82325Mandriva Linux Security Advisory : gnutls (MDVSA-2015:072)NessusMandriva Local Security Checks
medium
9265VLC Media Player < 2.1.5 Multiple VulnerabilitiesNessus Network MonitorWeb Clients
medium
80632Oracle Solaris Third-Party Patch Update : gnutls (multiple_vulnerabilities_in_gnutls)NessusSolaris Local Security Checks
medium
79108RHEL 6 : rhev-hypervisor6 (RHSA-2014:0815)NessusRed Hat Local Security Checks
medium
78626VLC Media Player < 2.1.5 Multiple VulnerabilitiesNessusWindows
critical
78295Amazon Linux AMI : gnutls (ALAS-2014-352)NessusAmazon Linux Local Security Checks
medium
76893RHEL 7 : gnutls (RHSA-2014:0684)NessusRed Hat Local Security Checks
medium
76731Oracle Linux 7 : gnutls (ELSA-2014-0684)NessusOracle Linux Local Security Checks
medium
76061GLSA-201406-09 : GnuTLS: Multiple vulnerabilitiesNessusGentoo Local Security Checks
medium
75384openSUSE Security Update : gnutls (openSUSE-SU-2014:0763-1)NessusSuSE Local Security Checks
medium
74417Mandriva Linux Security Advisory : gnutls (MDVSA-2014:108)NessusMandriva Local Security Checks
medium
74413Fedora 19 : mingw-gnutls-3.1.25-1.fc19 (2014-6963)NessusFedora Local Security Checks
medium
74410Fedora 20 : mingw-gnutls-3.1.25-1.fc20 (2014-6953)NessusFedora Local Security Checks
medium
74403Fedora 19 : gnutls-3.1.20-5.fc19 (2014-6881)NessusFedora Local Security Checks
medium
74329Slackware 13.0 / 13.1 / 13.37 / 14.0 / 14.1 / current : gnutls (SSA:2014-156-01)NessusSlackware Local Security Checks
medium
74321SuSE 11.3 Security Update : gnutls (SAT Patch Number 9320)NessusSuSE Local Security Checks
medium
74318FreeBSD : gnutls -- client-side memory corruption (9733c480-ebff-11e3-970b-206a8a720317)NessusFreeBSD Local Security Checks
medium
74316Fedora 20 : gnutls-3.1.25-1.fc20 (2014-6891)NessusFedora Local Security Checks
medium
74310CentOS 6 : gnutls (CESA-2014:0595)NessusCentOS Local Security Checks
medium
74309CentOS 5 : gnutls (CESA-2014:0594)NessusCentOS Local Security Checks
medium
74306Scientific Linux Security Update : gnutls on SL6.x i386/x86_64 (20140603)NessusScientific Linux Local Security Checks
medium
74305Scientific Linux Security Update : gnutls on SL5.x i386/x86_64 (20140603)NessusScientific Linux Local Security Checks
medium
74302RHEL 6 : gnutls (RHSA-2014:0595)NessusRed Hat Local Security Checks
medium
74301RHEL 5 : gnutls (RHSA-2014:0594)NessusRed Hat Local Security Checks
medium
74297Oracle Linux 6 : gnutls (ELSA-2014-0595)NessusOracle Linux Local Security Checks
medium
74296Oracle Linux 5 : gnutls (ELSA-2014-0594)NessusOracle Linux Local Security Checks
medium
74295FreeBSD : gnutls -- client-side memory corruption (027af74d-eb56-11e3-9032-000c2980a9f3)NessusFreeBSD Local Security Checks
medium
74285Ubuntu 10.04 LTS / 12.04 LTS / 13.10 / 14.04 LTS : gnutls26 vulnerability (USN-2229-1)NessusUbuntu Local Security Checks
medium
74280Debian DSA-2944-1 : gnutls26 - security updateNessusDebian Local Security Checks
medium