Denial of Service in GnuTLS Affected by Remote Attack via ECC Certificate
CVE-2014-8564
Currently unrated
Summary
A vulnerability in the _gnutls_ecc_ansi_x963_export function within GnuTLS versions prior to 3.1.28, 3.2.20, and 3.3.10 allows remote attackers to perform an out-of-bounds write. This can be executed through specially crafted Elliptic Curve Cryptography (ECC) certificates or certificate signing requests (CSRs). The flaw relates to issues in generating key IDs, leading to possible denial of service conditions.
References
Timeline
Vulnerability published
Vulnerability Reserved