CVE-2012-1573
Publication date 26 March 2012
Last updated 24 July 2024
Ubuntu priority
gnutls_cipher.c in libgnutls in GnuTLS before 2.12.17 and 3.x before 3.0.15 does not properly handle data encrypted with a block cipher, which allows remote attackers to cause a denial of service (heap memory corruption and application crash) via a crafted record, as demonstrated by a crafted GenericBlockCipher structure.
Status
Package | Ubuntu Release | Status |
---|---|---|
gnutls13 | ||
16.04 LTS xenial | Not in release | |
14.04 LTS trusty | Not in release | |
gnutls26 | ||
16.04 LTS xenial | Not in release | |
14.04 LTS trusty |
Fixed 2.12.14-5ubuntu3
|
|
gnutls28 | ||
16.04 LTS xenial |
Not affected
|
|
14.04 LTS trusty | Not in release | |
Patch details
Package | Patch details |
---|---|
gnutls13 | |
gnutls26 | |
gnutls28 |
References
Related Ubuntu Security Notices (USN)
- USN-1418-1
- GnuTLS vulnerabilities
- 5 April 2012