Buffer overflow in the gnutls_session_get_data function in lib/gnutls_session.c in GnuTLS 2.12.x before 2.12.14 and 3.x before 3.0.7, when used on a client that performs nonstandard session resumption, allows remote TLS servers to cause a denial of service (application crash) via a large SessionTicket.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: redhat
Published: 2011-12-08T20:00:00
Updated: 2024-08-07T00:01:51.259Z
Reserved: 2011-10-18T00:00:00
Link: CVE-2011-4128
Vulnrichment
No data.
NVD
Status : Modified
Published: 2011-12-08T20:55:00.890
Modified: 2023-11-07T02:09:15.883
Link: CVE-2011-4128
Redhat