Double Free Vulnerability in GnuTLS Affecting Multiple Versions
CVE-2015-6251

Currently unrated

Key Information:

Vendor
Gnu
Status
Vendor
CVE Published:
24 August 2015

Summary

A double free vulnerability in GnuTLS allows remote attackers to exploit a flaw in the handling of Distinguished Name (DN) entries in certificates. By crafting a certificate with a lengthy DN, an attacker can trigger a denial of service condition, potentially disrupting normal operation of applications utilizing GnuTLS. This vulnerability affects versions prior to 3.3.17 and 3.4.x before 3.4.4, highlighting the importance of prompt updates to mitigate risks.

References

EPSS Score

6% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.