CVE-2017-7507

high
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

GnuTLS version 3.5.12 and earlier is vulnerable to a NULL pointer dereference while decoding a status response TLS extension with valid contents. This could lead to a crash of the GnuTLS server application.

References

http://www.debian.org/security/2017/dsa-3884

http://www.securityfocus.com/bid/99102

https://access.redhat.com/errata/RHSA-2017:2292

https://www.gnutls.org/security.html#GNUTLS-SA-2017-4

Details

Source: MITRE

Published: 2017-06-16

Updated: 2018-01-05

Type: CWE-476

Risk Information

CVSS v2

Base Score: 5

Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Impact Score: 2.9

Exploitability Score: 10

Severity: MEDIUM

CVSS v3

Base Score: 7.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Impact Score: 3.6

Exploitability Score: 3.9

Severity: HIGH

Vulnerable Software

Configuration 1

OR

cpe:2.3:a:gnu:gnutls:*:*:*:*:*:*:*:* versions up to 3.5.12 (inclusive)

Tenable Plugins

View all (15 total)

IDNameProductFamilySeverity
111887Photon OS 1.0: Binutils / C / Dnsmasq / Git / Gnutls / Krb5 / Linux / Mercurial / Mesos / Nginx PHSA-2017-0038 (deprecated)NessusPhotonOS Local Security Checks
high
103850GLSA-201710-15 : GnuTLS: Denial of ServiceNessusGentoo Local Security Checks
high
103062EulerOS 2.0 SP2 : gnutls (EulerOS-SA-2017-1204)NessusHuawei Local Security Checks
critical
103061EulerOS 2.0 SP1 : gnutls (EulerOS-SA-2017-1203)NessusHuawei Local Security Checks
critical
102759CentOS 7 : gnutls (CESA-2017:2292)NessusCentOS Local Security Checks
critical
102642Scientific Linux Security Update : gnutls on SL7.x x86_64 (20170801)NessusScientific Linux Local Security Checks
critical
102303Oracle Linux 7 : gnutls (ELSA-2017-2292)NessusOracle Linux Local Security Checks
critical
102116RHEL 7 : gnutls (RHSA-2017:2292)NessusRed Hat Local Security Checks
critical
101759openSUSE Security Update : gnutls (openSUSE-2017-824)NessusSuSE Local Security Checks
high
101746Fedora 26 : gnutls (2017-f0d48eabe6)NessusFedora Local Security Checks
high
101660Fedora 26 : mingw-gnutls (2017-7936341c80)NessusFedora Local Security Checks
high
101393SUSE SLED12 / SLES12 Security Update : gnutls (SUSE-SU-2017:1838-1)NessusSuSE Local Security Checks
high
100852Debian DSA-3884-1 : gnutls28 - security updateNessusDebian Local Security Checks
high
100781Ubuntu 14.04 LTS / 16.04 LTS / 16.10 / 17.04 : gnutls26, gnutls28 vulnerabilities (USN-3318-1)NessusUbuntu Local Security Checks
high
100736Fedora 25 : gnutls (2017-f646217583)NessusFedora Local Security Checks
high