Denial of Service in GnuTLS Affected by Remote Attack via ECC Certificate
CVE-2014-8564

Currently unrated

Key Information:

Vendor
Gnu
Status
Vendor
CVE Published:
13 November 2014

Summary

A vulnerability in the _gnutls_ecc_ansi_x963_export function within GnuTLS versions prior to 3.1.28, 3.2.20, and 3.3.10 allows remote attackers to perform an out-of-bounds write. This can be executed through specially crafted Elliptic Curve Cryptography (ECC) certificates or certificate signing requests (CSRs). The flaw relates to issues in generating key IDs, leading to possible denial of service conditions.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.