CVE-2013-2116
Publication date 29 May 2013
Last updated 24 July 2024
Ubuntu priority
The _gnutls_ciphertext2compressed function in lib/gnutls_cipher.c in GnuTLS 2.12.23 allows remote attackers to cause a denial of service (buffer over-read and crash) via a crafted padding length. NOTE: this might be due to an incorrect fix for CVE-2013-0169.
Status
Package | Ubuntu Release | Status |
---|---|---|
gnutls26 | 14.04 LTS trusty |
Fixed 2.12.23-1ubuntu2
|
gnutls28 | 14.04 LTS trusty | Not in release |
Notes
References
Related Ubuntu Security Notices (USN)
- USN-1843-1
- GnuTLS vulnerability
- 29 May 2013