USN-7281-1: GnuTLS vulnerability
Bing Shi discovered that GnuTLS incorrectly handled decoding certain DER-encoded certificates. A remote attacker could possibly use this issue to cause GnuTLS to consume resources, leading to a denial of service.
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-7281-1?
The severity of USN-7281-1 is significant as it allows for a denial of service due to resource consumption.
How do I fix USN-7281-1?
To fix USN-7281-1, update your GnuTLS package to the latest version specified in the advisory corresponding to your Ubuntu release.
What systems are affected by USN-7281-1?
USN-7281-1 affects multiple versions of Ubuntu, specifically those using libgnutls30t64 versions below the specified remedies.
Can USN-7281-1 be exploited remotely?
Yes, a remote attacker can exploit USN-7281-1 to cause a denial of service.
What should I do if I can't update due to USN-7281-1?
If you cannot update to mitigate USN-7281-1, consider implementing firewall rules to restrict access to vulnerable services.