REDHAT-BUG-2359621: Medium severity GNUTLS GNUTLS vulnerability
A heap-buffer-overread vulnerability exists in GnuTLS (confirmed in version 3.8.9) due to unsafe handling of the Certificate Transparency (CT) Signed Certificate Timestamp (SCT) extension during X.509 certificate parsing. The vulnerability can be triggered by a malicious peer presenting a crafted certificate containing a malformed SCT extension (OID 1.3.6.1.4.1.11129.2.4.2). This overread may lead to disclosure of heap memory contents to attackers if the SCT logid is logged, exported, or otherwise exposed by the application consuming the GnuTLS client library.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2359621?
The severity of REDHAT-BUG-2359621 is high due to the heap-buffer-overread vulnerability.
Which version of GnuTLS is affected by REDHAT-BUG-2359621?
GnuTLS version 3.8.9 is confirmed to be affected by the vulnerability REDHAT-BUG-2359621.
How can I fix REDHAT-BUG-2359621?
Fix REDHAT-BUG-2359621 by updating to a patched version of GnuTLS that addresses the heap-buffer-overread issue.
What type of vulnerability is REDHAT-BUG-2359621?
REDHAT-BUG-2359621 is classified as a heap-buffer-overread vulnerability.
Can REDHAT-BUG-2359621 be exploited by a malicious peer?
Yes, REDHAT-BUG-2359621 can be exploited when a malicious peer presents a crafted certificate during X.509 certificate parsing.