Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
X.509 Certificate Signature Verification in Gnu transport layer security library (GnuTLS) 1.0.16 allows remote attackers to cause a denial of service (CPU consumption) via certificates containing long chains and signed with large RSA keys.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
GnuTLS证书链验证漏洞
Vulnerability Description
GnuTLS是一款提供可靠传输层加密的库。 GnuTLS库对X.509证书链验证存在问题,远程攻击者可以利用这个漏洞对使用GnuTLS的机器进行拒绝服务攻击。 GnuTLS库从开头到最后对root证书链的签字进行检查,不过没有限制KEYS的大小和证书链的长度,因此攻击者可以构建那些选定大小的RSA KEY签名的证书链进行验证。问题存在于选择的KEY大小,如使用复杂的RSA KEYS(如使用32768位RSA KEY签名)进行校验时将比1024位RSA KEY多花1024倍时间,因此如果攻击者提供超大的KE
CVSS Information
N/A
Vulnerability Type
N/A