CVE-2006-7239
Publication date 24 May 2010
Last updated 24 July 2024
Ubuntu priority
The _gnutls_x509_oid2mac_algorithm function in lib/gnutls_algorithms.c in GnuTLS before 1.4.2 allows remote attackers to cause a denial of service (crash) via a crafted X.509 certificate that uses a hash algorithm that is not supported by GnuTLS, which triggers a NULL pointer dereference.
Status
Package | Ubuntu Release | Status |
---|---|---|
gnutls11 | ||
gnutls12 | ||
gnutls13 | ||
gnutls26 | ||
Notes
jdstrand
gnutls11 doesn't have the affected code: _gnutls_x509_oid2mac_algorithm located in lib/x509/common.c which compares to #defines from x509.h, not a pointer Hardy (gnutls13) and higher already have the corrected code
References
Related Ubuntu Security Notices (USN)
- USN-948-1
- GnuTLS vulnerability
- 3 June 2010