FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

gnutls -- double free in certificate DN decoding

Affected packages
gnutls < 3.3.17

Details

VuXML ID ec6a2a1e-429d-11e5-9daa-14dae9d210b8
Discovery 2015-07-20
Entry 2015-08-14
Modified 2015-08-18

gnutls.org reports:

Kurt Roeckx reported that decoding a specific certificate with very long DistinguishedName (DN) entries leads to double free, which may result to a denial of service. Since the DN decoding occurs in almost all applications using certificates it is recommended to upgrade the latest GnuTLS version fixing the issue. Recommendation: Upgrade to GnuTLS 3.4.4, or 3.3.17.

References

CVE Name CVE-2015-6251
Message http://seclists.org/oss-sec/2015/q3/308
URL http://www.gnutls.org/security.html#GNUTLS-SA-2015-3
URL https://gitlab.com/gnutls/gnutls/commit/272854367efc130fbd4f1a51840d80c630214e12