The _gnutls_x509_oid2mac_algorithm function in lib/gnutls_algorithms.c in GnuTLS before 1.4.2 allows remote attackers to cause a denial of service (crash) via a crafted X.509 certificate that uses a hash algorithm that is not supported by GnuTLS, which triggers a NULL pointer dereference.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 00:24
Type | Values Removed | Values Added |
---|---|---|
References | () http://lists.gnupg.org/pipermail/gnutls-dev/2006-August/001190.html - | |
References | () http://lists.gnupg.org/pipermail/gnutls-dev/2006-August/001192.html - Patch | |
References | () http://www.gnu.org/software/gnutls/security.html - Vendor Advisory |
Information
Published : 2010-05-24 19:30
Updated : 2024-11-21 00:24
NVD link : CVE-2006-7239
Mitre link : CVE-2006-7239
CVE.ORG link : CVE-2006-7239
JSON object : View
Products Affected
gnu
- gnutls
CWE
CWE-310
Cryptographic Issues