GnuTLS "read_server_hello()" Memory Corruption Vulnerability

  Severity: MEDIUM
  CVE Identifier: CVE-2014-3466
  Advisory Date: JUL 21, 2015

  DESCRIPTION

Buffer overflow in the read_server_hello function in lib/gnutls_handshake.c in GnuTLS before 3.1.25, 3.2.x before 3.2.15, and 3.3.x before 3.3.4 allows remote servers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a long session id in a ServerHello message.

  TREND MICRO PROTECTION INFORMATION

Apply associated Trend Micro DPI Rules.

  SOLUTION

  Trend Micro Deep Security DPI Rule Number: 1006084
  Trend Micro Deep Security DPI Rule Name: 1006084 - GnuTLS "read_server_hello()" Memory Corruption Vulnerability

  AFFECTED SOFTWARE AND VERSION

  • gnu gnutls 3.1.0
  • gnu gnutls 3.1.1
  • gnu gnutls 3.1.10
  • gnu gnutls 3.1.11
  • gnu gnutls 3.1.12
  • gnu gnutls 3.1.13
  • gnu gnutls 3.1.14
  • gnu gnutls 3.1.15
  • gnu gnutls 3.1.16
  • gnu gnutls 3.1.17
  • gnu gnutls 3.1.18
  • gnu gnutls 3.1.19
  • gnu gnutls 3.1.2
  • gnu gnutls 3.1.20
  • gnu gnutls 3.1.21
  • gnu gnutls 3.1.22
  • gnu gnutls 3.1.23
  • gnu gnutls 3.1.24
  • gnu gnutls 3.1.3
  • gnu gnutls 3.1.4
  • gnu gnutls 3.1.5
  • gnu gnutls 3.1.6
  • gnu gnutls 3.1.7
  • gnu gnutls 3.1.8
  • gnu gnutls 3.1.9
  • gnu gnutls 3.2.0
  • gnu gnutls 3.2.1
  • gnu gnutls 3.2.10
  • gnu gnutls 3.2.11
  • gnu gnutls 3.2.12
  • gnu gnutls 3.2.12.1
  • gnu gnutls 3.2.13
  • gnu gnutls 3.2.14
  • gnu gnutls 3.2.2
  • gnu gnutls 3.2.3
  • gnu gnutls 3.2.4
  • gnu gnutls 3.2.5
  • gnu gnutls 3.2.6
  • gnu gnutls 3.2.7
  • gnu gnutls 3.2.8
  • gnu gnutls 3.2.8.1
  • gnu gnutls 3.2.9
  • gnu gnutls 3.3.0
  • gnu gnutls 3.3.1
  • gnu gnutls 3.3.2
  • gnu gnutls 3.3.3

Featured Stories