CVE-2005-1431: Medium severity GNU GnuTLS vulnerability
Published May 3, 2005
·Updated
The "record packet parsing" in GnuTLS 1.2 before 1.2.3 and 1.0 before 1.0.25 allows remote attackers to cause a denial of service, possibly related to padding bytes in gnutilscipher.c.
Affected Software
10 affected components
GNU GnuTLS=1.0.20
GNU GnuTLS=1.0.24
GNU GnuTLS=1.0.21
GNU GnuTLS=1.0.19
GNU GnuTLS=1.2.1
GNU GnuTLS=1.2.2
GNU GnuTLS=1.2.0
GNU GnuTLS=1.0.18
GNU GnuTLS=1.0.23
GNU GnuTLS=1.0.22
Event History
May 3, 2005
CVE Published
04:00 AM
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-1431?
CVE-2005-1431 is classified as a denial of service vulnerability.
2
How do I fix CVE-2005-1431?
To fix CVE-2005-1431, upgrade GnuTLS to version 1.2.3 or later for the 1.2 series or to 1.0.25 or later for the 1.0 series.
3
Which versions of GnuTLS are affected by CVE-2005-1431?
CVE-2005-1431 affects GnuTLS versions 1.0.18 to 1.0.24 and 1.2.0 to 1.2.2.
4
What impact does CVE-2005-1431 have on systems?
CVE-2005-1431 can allow remote attackers to trigger a denial of service condition in affected systems.
5
Can CVE-2005-1431 be exploited remotely?
Yes, CVE-2005-1431 can be exploited by remote attackers to cause denial of service.