Bug 1212459 (CVE-2015-3308) - CVE-2015-3308 gnutls: use-after-free flaw in CRL distribution points parsing
Summary: CVE-2015-3308 gnutls: use-after-free flaw in CRL distribution points parsing
Keywords:
Status: CLOSED WONTFIX
Alias: CVE-2015-3308
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1212463 1212464 1212465
Blocks: 1212469
TreeView+ depends on / blocked
 
Reported: 2015-04-16 13:07 UTC by Martin Prpič
Modified: 2021-06-13 21:04 UTC (History)
15 users (show)

Fixed In Version: gnutls 3.3.14
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2021-06-13 21:04:03 UTC
Embargoed:


Attachments (Terms of Use)

Description Martin Prpič 2015-04-16 13:07:39 UTC
A use-after-free flaw was found in the way GnuTLS parsed CRL distribution points. A specially crafted certificate could cause an application using GnuTLS to crash.

Upstream patches:

https://gitlab.com/gnutls/gnutls/commit/d6972be33264ecc49a86cd0958209cd7363af1e9
https://gitlab.com/gnutls/gnutls/commit/053ae65403216acdb0a4e78b25ad66ee9f444f02

Comment 1 Martin Prpič 2015-04-16 13:20:17 UTC
Created mingw-gnutls tracking bugs for this issue:

Affects: fedora-21 [bug 1212464]
Affects: epel-7 [bug 1212465]

Comment 2 Martin Prpič 2015-04-16 13:20:21 UTC
Created gnutls tracking bugs for this issue:

Affects: fedora-21 [bug 1212463]

Comment 3 Martin Prpič 2015-04-16 13:22:24 UTC
The affected function, gnutls_x509_ext_import_crl_dist_points(), was introduced in GnuTLS version 3.3.0:

http://gnutls.org/manual/html_node/X509-certificate-API.html#gnutls_005fx509_005fext_005fimport_005fcrl_005fdist_005fpoints-1

Comment 4 Martin Prpič 2015-04-16 13:22:42 UTC
Statement:

This issue did not affect the versions of gnutls as shipped with Red Hat Enterprise Linux 5 and 6. This issue affects the version of gnutls as shipped with Red Hat Enterprise Linux 7. A further update may address this flaw.

Comment 6 Fedora Update System 2015-05-03 00:47:36 UTC
mingw-gnutls-3.3.14-1.el7, mingw-libtasn1-4.4-1.el7, mingw-p11-kit-0.20.7-1.el7 has been pushed to the Fedora EPEL 7 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 9 Product Security DevOps Team 2021-06-13 21:04:03 UTC
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):

https://access.redhat.com/security/cve/cve-2015-3308


Note You need to log in before you can comment on or make changes to this bug.