[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248268

 
 

909

 
 

195051

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

GnuTLS - (bulletinjul2017)

ID: oval:org.secpod.oval:def:2101251Date: (C)2019-12-30   (M)2024-01-29
Class: PATCHFamily: unix




The gnutls_ocsp_resp_check_crt function in lib/x509/ocsp.c in GnuTLS before 3.4.15 and 3.5.x before 3.5.4 does not verify the serial length of an OCSP response, which might allow remote attackers to bypass an intended certificate validation mechanism via vectors involving trailing bytes left by gnutls_malloc.

Platform:
Sun Solaris 11
Product:
library/gnutls-3
Reference:
bulletinjul2017
CVE-2016-7444
CVE-2016-4456
CVE    2
CVE-2016-4456
CVE-2016-7444
CPE    1
cpe:/o:oracle:solaris:11

© SecPod Technologies