Direct naar de inhoud
Kritieke cyberalerts voor jouw sector & systemen — direct in je inbox. Aanmelden →
cybernieuws.nl Cybersecurity en informatiebeveiling nieuws alerts live · 2 min 106 bronnen 1 kritiek 1 vandaag
CVE's Videos

← Terug naar CVE-database

CVE-2014-8564

MEDIUM · 5.0 CVSS Gepubliceerd: CWE-310

Beschrijving

The _gnutls_ecc_ansi_x963_export function in gnutls_ecc.c in GnuTLS 3.x before 3.1.28, 3.2.x before 3.2.20, and 3.3.x before 3.3.10 allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted (1) Elliptic Curve Cryptography (ECC) certificate or (2) certificate signing requests (CSR), related to generating key IDs.

Vendors

Gnu Redhat Opensuse Canonical

Affected products

Gnutls Enterprise Linux Desktop Enterprise Linux Hpc Node Enterprise Linux Server Enterprise Linux Workstation Opensuse Ubuntu Linux

References