Candidate: CVE-2016-4456 PublicDate: 2017-08-08 21:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4456 http://gnutls.org/security.html#GNUTLS-SA-2016-1 http://www.openwall.com/lists/oss-security/2016/06/07/2 Description: The "GNUTLS_KEYLOGFILE" environment variable in gnutls 3.4.12 allows remote attackers to overwrite and corrupt arbitrary files in the filesystem. Ubuntu-Description: Notes: mdeslaur> introduced in 3.4.12 Bugs: Priority: medium Discovered-by: Nikos Mavrogiannopoulos Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N [7.5 HIGH] nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N [7.5 HIGH] Patches_gnutls28: upstream_gnutls28: released (3.4.13-1) precise_gnutls28: not-affected trusty_gnutls28: not-affected trusty/esm_gnutls28: DNE (trusty was not-affected) vivid/stable-phone-overlay_gnutls28: not-affected vivid/ubuntu-core_gnutls28: not-affected wily_gnutls28: not-affected xenial_gnutls28: not-affected esm-infra/xenial_gnutls28: not-affected devel_gnutls28: not-affected (3.4.11-4ubuntu1)