Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Buffer overflow in the gnutls_session_get_data function in lib/gnutls_session.c in GnuTLS 2.12.x before 2.12.14 and 3.x before 3.0.7, when used on a client that performs nonstandard session resumption, allows remote TLS servers to cause a denial of service (application crash) via a large SessionTicket.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
GnuTLS ‘gnutls_session_get_data()’ 缓冲区溢出漏洞
Vulnerability Description
GnuTLS是比利时Nikos Mavrogiannopoulos和瑞典Simon Josefsson软件开发者共同研发的一个免费的用于实现SSL、TLS和DTLS协议的安全通信库。 GnuTLS在"gnutls_session_get_data()"函数(lib/gnutls_session.c)的实现上存在漏洞。攻击者可通过诱使使用该函数的客户端连接到恶意服务器造成缓冲区溢出。
CVSS Information
N/A
Vulnerability Type
N/A