OSVDB ID: 8278

Title: GnuTLS X.509 Certificate Signature Verification DoS

Info

Disclosure

Aug 02, 2004

Discovery

Unknown

Dates

Exploit

Aug 02, 2004

Solution

Unknown

Description

GnuTLS contains a flaw that may allow a remote denial of service. The issue is due to the product not limiting the length of a certificate chain or the size of the RSA or DSA keys used to sign a X.509 certificate. An attacker can craft a certificate using very large keys causing the product to consume excessive CPU resources when trying to validate the certificate chain resulting in a denial of service condition, and will result in loss of availability for the platform.

Classification

Location: Remote / Network Access
Attack Type: Denial of Service
Impact: Loss of Availability
Exploit: Exploit Public

Solution

Upgrade to version 1.0.17 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.

Products

GNU

GnuTLS

1.0.16

References

Credit

  • Patrik Hornik - patrikhornik.sk -


Direct URL: http://osvdb.org/8278