Wind River Support Network

HomeDefectsLIN8-4877
Fixed

LIN8-4877 : Security Advisory - gnutls - CVE-2016-7444

Created: Oct 16, 2016    Updated: Dec 3, 2018
Resolved Date: Oct 18, 2016
Found In Version: 8.0
Fix Version: 8.0.0.11
Severity: Standard
Applicable for: Wind River Linux 8
Component/s: Userspace

Description

The gnutls_ocsp_resp_check_crt function in lib/x509/ocsp.c in GnuTLS before 3.4.15 and 3.5.x before 3.5.4 does not verify the serial length of an OCSP response, which might allow remote attackers to bypass an intended certificate validation mechanism via vectors involving trailing bytes left by gnutls_malloc.

http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-7444

Other Downloads


CVEs


Live chat
Online