CVE-2017-5335: High severity openSUSE Leap vulnerability
A vulnerability was found in gnutls. There was an insufficient error checking in the stream reading functions. While parsing a maliciously crafted OpenPGP certificate an out of memory error could occur.
References:
http://seclists.org/oss-sec/2017/q1/51 https://gnutls.org/security.html#GNUTLS-SA-2017-2
Upstream patch:
https://gitlab.com/gnutls/gnutls/commit/49be4f7b82eba2363bb8d4090950dad976a77a3a
Other sources
The stream reading functions in lib/opencdk/read-packet.c in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allow remote attackers to cause a denial of service (out-of-memory error and crash) via a crafted OpenPGP certificate.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/gnutlsto a version that resolves this vulnerability.Fixed in 3.3.26 - Upgrade
Upgrade
redhat/gnutlsto a version that resolves this vulnerability.Fixed in 3.5.8 - Upgrade
Upgrade
debian/gnutls28to a version that resolves this vulnerability.Fixed in 3.7.1-5+deb11u5Fixed in 3.7.1-5+deb11u7Fixed in 3.7.9-2+deb12u4Fixed in 3.8.9-2 - Upgrade
Upgrade
gnutls/gnutlsto a version that resolves this vulnerability.Fixed in 3.3.26 - Upgrade
Upgrade
gnutls/gnutlsto a version that resolves this vulnerability.Fixed in 3.5.8
Event History
Frequently Asked Questions
What is the severity of CVE-2017-5335?
CVE-2017-5335 has a medium severity rating due to potential denial of service from out of memory errors.
How do I fix CVE-2017-5335?
To fix CVE-2017-5335, update to GnuTLS version 3.3.26 or later, or 3.5.8 or later.
What types of systems are affected by CVE-2017-5335?
CVE-2017-5335 affects various systems running vulnerable versions of GnuTLS, including Red Hat and Debian distributions.
What is the nature of the CVE-2017-5335 vulnerability?
CVE-2017-5335 involves insufficient error checking in GnuTLS's stream reading functions leading to crashes from malformed OpenPGP certificates.
Is CVE-2017-5335 exploitable in a networked environment?
Yes, CVE-2017-5335 can be exploited in networked environments where malicious certificates can be presented to the GnuTLS library.