Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 494066 - net-libs/gnutls: Denial of Service (incomplete fix for CVE-2013-4466) (CVE-2013-4487)
Summary: net-libs/gnutls: Denial of Service (incomplete fix for CVE-2013-4466) (CVE-20...
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal trivial (vote)
Assignee: Gentoo Security
URL:
Whiteboard: ~3 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2013-12-12 17:17 UTC by GLSAMaker/CVETool Bot
Modified: 2013-12-15 10:11 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description GLSAMaker/CVETool Bot gentoo-dev 2013-12-12 17:17:58 UTC
CVE-2013-4487 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-4487):
  Off-by-one error in the dane_raw_tlsa in the DANE library (libdane) in
  GnuTLS 3.1.x before 3.1.16 and 3.2.x before 3.2.6 allows remote servers to
  cause a denial of service (memory corruption) via a response with more than
  four DANE entries.  NOTE: this issue is due to an incomplete fix for
  CVE-2013-4466.


Needs cleanup.
Comment 1 Alon Bar-Lev (RETIRED) gentoo-dev 2013-12-12 17:22:06 UTC
done
Comment 2 Sergey Popov gentoo-dev 2013-12-15 10:11:03 UTC
Thanks for the cleanup

Closing as noglsa