PublicDateAtUSN: 2017-01-11 Candidate: CVE-2017-5337 PublicDate: 2017-03-24 15:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5337 https://gnutls.org/security.html#GNUTLS-SA-2017-2 http://seclists.org/oss-sec/2017/q1/51 https://ubuntu.com/security/notices/USN-3183-1 Description: Multiple heap-based buffer overflows in the read_attribute function in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allow remote attackers to have unspecified impact via a crafted OpenPGP certificate. Ubuntu-Description: Notes: mdeslaur> reproducer https://gitlab.com/gnutls/gnutls/commit/d949c6266ce64f5c2419f8c7cf4a196122fff9d7 mdeslaur> https://gitlab.com/gnutls/gnutls/commit/e08b66b7cb4bc3f7ad56d081f0357ec1d39aa4ec Bugs: Priority: medium Discovered-by: Assigned-to: mdeslaur CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H [9.8 CRITICAL] Patches_gnutls26: upstream_gnutls26: needs-triage precise_gnutls26: released (2.12.14-5ubuntu3.13) precise/esm_gnutls26: released (2.12.14-5ubuntu3.13) trusty_gnutls26: released (2.12.23-12ubuntu2.6) trusty/esm_gnutls26: released (2.12.23-12ubuntu2.6) vivid/ubuntu-core_gnutls26: DNE vivid/stable-phone-overlay_gnutls26: DNE xenial_gnutls26: DNE yakkety_gnutls26: DNE zesty_gnutls26: DNE artful_gnutls26: DNE bionic_gnutls26: DNE cosmic_gnutls26: DNE disco_gnutls26: DNE devel_gnutls26: DNE Patches_gnutls28: upstream: https://gitlab.com/gnutls/gnutls/commit/94fcf1645ea17223237aaf8d19132e004afddc1a upstream: https://gitlab.com/gnutls/gnutls/commit/6231a4a087f9fdbd5f5f274e80c7a71e3e45b9c8 (3.3) upstream_gnutls28: needs-triage precise_gnutls28: ignored (reached end-of-life) precise/esm_gnutls28: DNE (precise was needed) trusty_gnutls28: ignored (reached end-of-life) trusty/esm_gnutls28: DNE (trusty was needed) vivid/ubuntu-core_gnutls28: ignored (reached end-of-life) vivid/stable-phone-overlay_gnutls28: ignored (reached end-of-life) xenial_gnutls28: released (3.4.10-4ubuntu1.2) esm-infra/xenial_gnutls28: released (3.4.10-4ubuntu1.2) yakkety_gnutls28: released (3.5.3-5ubuntu1.1) zesty_gnutls28: released (3.5.6-4ubuntu3) artful_gnutls28: released (3.5.6-4ubuntu3) bionic_gnutls28: released (3.5.6-4ubuntu3) cosmic_gnutls28: released (3.5.6-4ubuntu3) disco_gnutls28: released (3.5.6-4ubuntu3) devel_gnutls28: released (3.5.6-4ubuntu3)