Beveiligingsadvies

CVE-2016-7444

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2016-09-27 15:00:00
Laatst bijgewerkt 2024-08-06 01:57:47
Toegewezen door debian
CVSS-score geen score
Status PUBLISHED

Beschrijving

The gnutls_ocsp_resp_check_crt function in lib/x509/ocsp.c in GnuTLS before 3.4.15 and 3.5.x before 3.5.4 does not verify the serial length of an OCSP response, which might allow remote attackers to bypass an intended certificate validation mechanism via vectors involving trailing bytes left by gnutls_malloc.