CVE-2014-3466
Publication date 1 June 2014
Last updated 24 July 2024
Ubuntu priority
Buffer overflow in the read_server_hello function in lib/gnutls_handshake.c in GnuTLS before 3.1.25, 3.2.x before 3.2.15, and 3.3.x before 3.3.4 allows remote servers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a long session id in a ServerHello message.
Status
Package | Ubuntu Release | Status |
---|---|---|
gnutls26 | ||
14.04 LTS trusty |
Fixed 2.12.23-12ubuntu2.1
|
|
gnutls28 | ||
14.04 LTS trusty |
Fixed 3.2.11-2ubuntu1.1
|
|
References
Related Ubuntu Security Notices (USN)
- USN-2229-1
- GnuTLS vulnerability
- 2 June 2014