Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The gnutls_x509_crt_get_serial function in the GnuTLS library before 1.2.1, when running on big-endian, 64-bit platforms, calls the asn1_read_value with a pointer to the wrong data type and the wrong length value, which allows remote attackers to bypass the certificate revocation list (CRL) check and cause a stack-based buffer overflow via a crafted X.509 certificate, related to extraction of a serial number.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
GnuTLS X.509证书序列号解码绕过安全检查漏洞
Vulnerability Description
GnuTLS是用于实现TLS加密协议的函数库。 GnuTLS从X.509证书获取序列号的方式存在漏洞。在64位的big endian平台上,这个漏洞可能允许绕过CRL检查,导致各种GnuTLS工具崩溃或执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A