CVE-2015-8313: Medium severity GNU GnuTLS vulnerability
Published Dec 20, 2019
·Updated
GnuTLS incorrectly validates the first byte of padding in CBC modes
Affected Software
6 affected componentsFixes available
GNU GnuTLS>=2.0.0<=2.12.24
Debian Debian Linux=7.0
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Debian Debian Linux=10.0
debian/gnutls28
3.7.1-5+deb11u53.7.1-5+deb11u83.7.9-2+deb12u53.7.9-2+deb12u63.8.9-3+deb13u13.8.9-3+deb13u23.8.11-33.8.12-2
Remediation
Patch Available
Event History
Dec 20, 2019
CVE Published
via MITRE·01:10 PM
Data Sourced
via MITRE·01:10 PM
Description
Feb 19, 2026
Data Sourced
via Debian·12:01 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this GnuTLS vulnerability?
The vulnerability ID for this GnuTLS vulnerability is CVE-2015-8313.
2
What is the severity of CVE-2015-8313?
The severity of CVE-2015-8313 is medium with a severity value of 5.9.
3
What software is affected by CVE-2015-8313?
The software affected by CVE-2015-8313 includes GnuTLS versions 2.0.0 to 2.12.24, Debian Debian Linux versions 7.0 to 10.0, and the package gnutls28 with specific versions 3.6.7-4+deb10u8, 3.6.7-4+deb10u10, 3.7.1-5+deb11u3, 3.7.9-2, and 3.8.1-4.
4
How does CVE-2015-8313 affect GnuTLS?
CVE-2015-8313 affects GnuTLS by incorrectly validating the first byte of padding in CBC modes.
5
What is the Common Weakness Enumeration (CWE) ID for CVE-2015-8313?
The Common Weakness Enumeration (CWE) ID for CVE-2015-8313 is 203.