Total vulnerabilities in the database
An issue was discovered in GnuTLS before 3.6.15. A server can trigger a NULL pointer dereference in a TLS 1.3 client if a no_renegotiation alert is sent with unexpected timing, and then an invalid second handshake occurs. The crash happens in the application's error handling path, where the gnutls_deinit function is called after detecting a handshake failure.
Software | From | Fixed in |
---|---|---|
gnu / gnutls | - | 3.6.15 |
fedoraproject / fedora | 32 | 32.x |
fedoraproject / fedora | 33 | 33.x |
opensuse / leap | 15.1 | 15.1.x |
opensuse / leap | 15.2 | 15.2.x |
canonical / ubuntu_linux | 20.04 | 20.04.x |