CVE-2009-1415
Gnutls < 2.6.6 - Denial of Service
Title source: ruleDescription
lib/pk-libgcrypt.c in libgnutls in GnuTLS before 2.6.6 does not properly handle invalid DSA signatures, which allows remote attackers to cause a denial of service (application crash) and possibly have unspecified other impact via a malformed DSA key that triggers a (1) free of an uninitialized pointer or (2) double free.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Miroslav Kratochvil · cdoslinux
https://www.exploit-db.com/exploits/32964
References (13)
Scores
EPSS
0.1776
EPSS Percentile
95.1%
Details
CWE
CWE-824
Status
published
Products (1)
gnu/gnutls
< 2.6.6
Published
Apr 30, 2009
Tracked Since
Feb 18, 2026