CVE-2017-7507
HIGHGnuTLS <= 3.5.12 - Denial of Service via Status Response TLS Extension
Title source: llmDescription
GnuTLS version 3.5.12 and earlier is vulnerable to a NULL pointer dereference while decoding a status response TLS extension with valid contents. This could lead to a crash of the GnuTLS server application.
References (4)
Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/99102
Vendor Advisory vendor-advisory
x_refsource_redhat
https://access.redhat.com/errata/RHSA-2017:2292
Vendor Advisory x_refsource_confirm
https://www.gnutls.org/security.html#GNUTLS-SA-2017-4
Third Party Advisory vendor-advisory
x_refsource_debian
http://www.debian.org/security/2017/dsa-3884
Scores
CVSS v3
7.5
EPSS
0.0068
EPSS Percentile
71.7%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Details
CWE
CWE-476
Status
published
Products (2)
gnu/gnutls
< 3.5.12
GnuTLS/gnutls
3.5.12
Published
Jun 16, 2017
Tracked Since
Feb 18, 2026