PublicDateAtUSN: 2017-01-11 Candidate: CVE-2017-5335 PublicDate: 2017-03-24 15:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5335 https://gnutls.org/security.html#GNUTLS-SA-2017-2 http://seclists.org/oss-sec/2017/q1/51 https://ubuntu.com/security/notices/USN-3183-1 Description: The stream reading functions in lib/opencdk/read-packet.c in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allow remote attackers to cause a denial of service (out-of-memory error and crash) via a crafted OpenPGP certificate. Ubuntu-Description: Notes: mdeslaur> reproducer https://gitlab.com/gnutls/gnutls/commit/65ee81db857d3b44cec76aa94361abe5427430d8 Bugs: Priority: medium Discovered-by: Assigned-to: mdeslaur CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H [7.5 HIGH] Patches_gnutls26: upstream_gnutls26: needs-triage precise_gnutls26: released (2.12.14-5ubuntu3.13) precise/esm_gnutls26: released (2.12.14-5ubuntu3.13) trusty_gnutls26: released (2.12.23-12ubuntu2.6) trusty/esm_gnutls26: released (2.12.23-12ubuntu2.6) vivid/ubuntu-core_gnutls26: DNE vivid/stable-phone-overlay_gnutls26: DNE xenial_gnutls26: DNE yakkety_gnutls26: DNE zesty_gnutls26: DNE artful_gnutls26: DNE bionic_gnutls26: DNE cosmic_gnutls26: DNE disco_gnutls26: DNE devel_gnutls26: DNE Patches_gnutls28: upstream: https://gitlab.com/gnutls/gnutls/commit/49be4f7b82eba2363bb8d4090950dad976a77a3a upstream: https://gitlab.com/gnutls/gnutls/commit/61009ee749a27c90d141e3d4b2ebaebe9934422d (post 3.5.8) upstream: https://gitlab.com/gnutls/gnutls/commit/785af1ab577f899d2e54172ff120f404709bf172 (3.3) upstream_gnutls28: released (3.5.8-1) precise_gnutls28: ignored (reached end-of-life) precise/esm_gnutls28: DNE (precise was needed) trusty_gnutls28: ignored (reached end-of-life) trusty/esm_gnutls28: DNE (trusty was needed) vivid/stable-phone-overlay_gnutls28: ignored (reached end-of-life) vivid/ubuntu-core_gnutls28: ignored (reached end-of-life) xenial_gnutls28: released (3.4.10-4ubuntu1.2) esm-infra/xenial_gnutls28: released (3.4.10-4ubuntu1.2) yakkety_gnutls28: released (3.5.3-5ubuntu1.1) zesty_gnutls28: released (3.5.6-4ubuntu3) artful_gnutls28: released (3.5.6-4ubuntu3) bionic_gnutls28: released (3.5.6-4ubuntu3) cosmic_gnutls28: released (3.5.6-4ubuntu3) disco_gnutls28: released (3.5.6-4ubuntu3) devel_gnutls28: released (3.5.6-4ubuntu3)