REDHAT-BUG-2359620: Medium severity GnuTLS certtool vulnerability
A heap-buffer-overflow (off-by-one) vulnerability exists in the template parsing logic within the certtool utility of GnuTLS. The vulnerability specifically occurs when parsing certain multiline configuration options from a user-supplied template file, allowing an attacker to cause an out-of-bounds (OOB) NULL pointer write, resulting in memory corruption and potential denial-of-service (DoS).
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2359620?
REDHAT-BUG-2359620 is classified as a high severity vulnerability due to the potential for remote exploitation.
How do I fix REDHAT-BUG-2359620?
To fix REDHAT-BUG-2359620, upgrade to the latest version of GnuTLS certtool that includes the necessary patches.
What types of systems are affected by REDHAT-BUG-2359620?
Systems running GnuTLS certtool that utilize user-supplied template files for configuration are affected by REDHAT-BUG-2359620.
What is the impact of exploiting REDHAT-BUG-2359620?
Exploiting REDHAT-BUG-2359620 may lead to a heap buffer overflow, potentially allowing an attacker to execute arbitrary code.
How can I mitigate the risk of REDHAT-BUG-2359620 while waiting for a fix?
To mitigate the risk of REDHAT-BUG-2359620, avoid using untrusted template files with the certtool utility.