FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

gnutls -- double free in certificate DN decoding

Affected packages
gnutls < 3.3.17

Details

VuXML ID ec6a2a1e-429d-11e5-9daa-14dae9d210b8
Discovery 2015-07-20
Entry 2015-08-14
Modified 2015-08-18

gnutls.org reports:

Kurt Roeckx reported that decoding a specific certificate with very long DistinguishedName (DN) entries leads to double free, which may result to a denial of service. Since the DN decoding occurs in almost all applications using certificates it is recommended to upgrade the latest GnuTLS version fixing the issue. Recommendation: Upgrade to GnuTLS 3.4.4, or 3.3.17.

References

CVE Name CVE-2015-6251
Message http://seclists.org/oss-sec/2015/q3/308
URL http://www.gnutls.org/security.html#GNUTLS-SA-2015-3
URL https://gitlab.com/gnutls/gnutls/commit/272854367efc130fbd4f1a51840d80c630214e12

OSZAR »