CVE-2009-1415

Gnutls < 2.6.6 - Denial of Service

Title source: rule

Description

lib/pk-libgcrypt.c in libgnutls in GnuTLS before 2.6.6 does not properly handle invalid DSA signatures, which allows remote attackers to cause a denial of service (application crash) and possibly have unspecified other impact via a malformed DSA key that triggers a (1) free of an uninitialized pointer or (2) double free.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Miroslav Kratochvil · cdoslinux
https://www.exploit-db.com/exploits/32964

Scores

EPSS 0.1776
EPSS Percentile 95.1%

Details

CWE
CWE-824
Status published
Products (1)
gnu/gnutls < 2.6.6
Published Apr 30, 2009
Tracked Since Feb 18, 2026