Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Stack-based buffer overflow in the cdk_pk_get_keyid function in lib/opencdk/pubkey.c in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allows remote attackers to have unspecified impact via a crafted OpenPGP certificate.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
GnuTLS 缓冲区错误漏洞
Vulnerability Description
GnuTLS是比利时Nikos Mavrogiannopoulos和瑞典Simon Josefsson软件开发者共同研发的一个免费的用于实现SSL、TLS和DTLS协议的安全通信库。 GnuTLS 3.3.26之前的版本和3.5.8之前的3.5.x版本中的lib/opencdk/pubkey.c文件的‘cdk_pk_get_keyid’函数中存在基于栈的缓冲区溢出漏洞。远程攻击者可借助特制的OpenPGP证书利用该漏洞在受影响应用程序的上下文中执行任意代码,造成拒绝服务。
CVSS Information
N/A
Vulnerability Type
N/A