CVE-2017-5337: Buffer Overflow
A vulnerability was found in gnutls. A heap read overflow could occur while parsing maliciously crafted OpenPGP certificate.
References:
http://seclists.org/oss-sec/2017/q1/51 https://gnutls.org/security.html#GNUTLS-SA-2017-2
Upstream patch:
https://gitlab.com/gnutls/gnutls/commit/94fcf1645ea17223237aaf8d19132e004afddc1a
Other sources
Multiple heap-based buffer overflows in the readattribute function in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allow remote attackers to have unspecified impact via a crafted OpenPGP certificate.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/gnutlsto a version that resolves this vulnerability.Fixed in 3.3.26 - Upgrade
Upgrade
redhat/gnutlsto a version that resolves this vulnerability.Fixed in 3.5.8 - Upgrade
Upgrade
debian/gnutls28to a version that resolves this vulnerability.Fixed in 3.7.1-5+deb11u5Fixed in 3.7.1-5+deb11u7Fixed in 3.7.9-2+deb12u4Fixed in 3.8.9-2 - Upgrade
Upgrade
gnutls/gnutlsto a version that resolves this vulnerability.Fixed in 3.3.26 - Upgrade
Upgrade
gnutls/gnutlsto a version that resolves this vulnerability.Fixed in 3.5.8 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch 94fcf1645ea17223237aaf8d19132e004afddc1a
Event History
Frequently Asked Questions
What is the severity of CVE-2017-5337?
CVE-2017-5337 has been classified as a high severity vulnerability due to the potential for a heap read overflow.
How do I fix CVE-2017-5337?
To fix CVE-2017-5337, update the gnutls package to at least version 3.3.26 or 3.5.8, or the relevant patched versions for your distribution.
Which software versions are affected by CVE-2017-5337?
CVE-2017-5337 affects gnutls versions prior to 3.3.26 and 3.5.8, along with specific builds of gnutls28 on Debian.
What kind of exploitation is possible with CVE-2017-5337?
CVE-2017-5337 could allow attackers to trigger a heap read overflow by parsing a specially crafted OpenPGP certificate.
Is CVE-2017-5337 present in openSUSE?
Yes, CVE-2017-5337 affects specific versions of gnutls included in openSUSE Leap 42.1 and 42.2.