Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 281249 - =net-libs/gnutls-2.8.2 Memory overread Denial of Service
Summary: =net-libs/gnutls-2.8.2 Memory overread Denial of Service
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High trivial (vote)
Assignee: Gentoo Security
URL: http://git.savannah.gnu.org/gitweb/?p...
Whiteboard: ~4 [noglsa]
Keywords:
Depends on:
Blocks: 275695
  Show dependency tree
 
Reported: 2009-08-12 20:33 UTC by Robert Buchholz (RETIRED)
Modified: 2009-08-13 01:06 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Robert Buchholz (RETIRED) gentoo-dev 2009-08-12 20:33:41 UTC
Tomas Hoger of Red Hat pointed out that GnuTLS 2.8.2 contains an out of bounds read crash that is exposed via public API functions.

Discussion:
http://thread.gmane.org/gmane.comp.encryption.gpg.gnutls.devel/3725/focus=3768

Patch;
http://git.savannah.gnu.org/gitweb/?p=gnutls.git;a=commit;h=c12e7507562d5f168330acf1dd7db7cc2079cdf0
Comment 1 Arfrever Frehtes Taifersar Arahesis (RETIRED) gentoo-dev 2009-08-13 01:06:15 UTC
Fixed in net-libs/gnutls-2.8.2-r1.