« Volver al listado

CVE-2013-4466

Estado: ModificadaMedia (5)—

Buffer overflow in the dane_query_tlsa function in the DANE library (libdane) in GnuTLS 3.1.x before 3.1.15 and 3.2.x before 3.2.5 allows remote servers to cause a denial of service (memory corruption) via a response with more than four DANE entries.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2013-4466",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "secalert@redhat.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2013-11-20T14:12:30.350",
  "references": [
    {
      "url": "http://article.gmane.org/gmane.comp.encryption.gpg.gnutls.devel/7049",
      "tags": [
        "Patch"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://article.gmane.org/gmane.comp.encryption.gpg.gnutls.devel/7050",
      "tags": [
        "Patch"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.gnutls.org/security.html#GNUTLS-SA-2013-3",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2013/10/25/2",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://article.gmane.org/gmane.comp.encryption.gpg.gnutls.devel/7049",
      "tags": [
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://article.gmane.org/gmane.comp.encryption.gpg.gnutls.devel/7050",
      "tags": [
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.gnutls.org/security.html#GNUTLS-SA-2013-3",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2013/10/25/2",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-119"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Buffer overflow in the dane_query_tlsa function in the DANE library (libdane) in GnuTLS 3.1.x before 3.1.15 and 3.2.x before 3.2.5 allows remote servers to cause a denial of service (memory corruption) via a response with more than four DANE entries."
    },
    {
      "lang": "es",
      "value": "Desbordamiento de búfer en la función dane_query_tlsa de la librería DANE (libdane) en GnuTLS 3.1.x anterior a la versión 3.1.15 y 3.2.x anterior a 3.2.5 permite en servidores remotos provocar una denegación de servicio (corrupción de memoria) a través de una respuesta que implique más de 4 entradas DANE."
    }
  ],
  "lastModified": "2026-06-16T23:57:16.623",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:gnu:gnutls:3.1.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D91451B0-301B-430D-9D77-00F4AE91C10A"
            },
            {
              "criteria": "cpe:2.3:a:gnu:gnutls:3.1.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6917AC57-F49D-4EFC-920C-CCAFDF6174B0"
            },
            {
              "criteria": "cpe:2.3:a:gnu:gnutls:3.1.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E7ACCE21-A19D-4BE5-9BED-30C5A7418719"
            },
            {
              "criteria": "cpe:2.3:a:gnu:gnutls:3.1.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "344CCDAD-64EC-419C-995B-51F922AB9E39"
            },
            {
              "criteria": "cpe:2.3:a:gnu:gnutls:3.1.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "49DB8FC4-F84A-47FD-9586-CF02761152A5"
            },
            {
              "criteria": "cpe:2.3:a:gnu:gnutls:3.1.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A1B43AF4-E52B-46EA-81CF-D4DCAE82E7DD"
            },
            {
              "criteria": "cpe:2.3:a:gnu:gnutls:3.1.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D57BDDEB-090D-472C-9FB6-4555429860E5"
            },
            {
              "criteria": "cpe:2.3:a:gnu:gnutls:3.1.7:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6CB23D13-94D2-4FAE-AB76-8574E35E02AD"
            },
            {
              "criteria": "cpe:2.3:a:gnu:gnutls:3.1.8:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D45B0F5E-B4E1-471E-8CDD-85E09837839F"
            },
            {
              "criteria": "cpe:2.3:a:gnu:gnutls:3.1.9:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F430F4C6-A738-4E02-BE76-041F71335E62"
            },
            {
              "criteria": "cpe:2.3:a:gnu:gnutls:3.1.10:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F272E2DC-7E54-4034-B7BA-30966D57CDFA"
            },
            {
              "criteria": "cpe:2.3:a:gnu:gnutls:3.1.11:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "64EE97BB-D0EE-444A-96FA-D127892216F3"
            },
            {
              "criteria": "cpe:2.3:a:gnu:gnutls:3.1.12:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FB28F388-DE19-4C25-A838-949CA926C31A"
            },
            {
              "criteria": "cpe:2.3:a:gnu:gnutls:3.1.13:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "33DCAA09-7E8C-4C3E-901F-641681AA9E3C"
            },
            {
              "criteria": "cpe:2.3:a:gnu:gnutls:3.1.14:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "435C588C-A478-4FB8-A47D-2605CB39C331"
            },
            {
              "criteria": "cpe:2.3:a:gnu:gnutls:3.2.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "827A375E-8045-4A81-AB7C-11A89E862518"
            },
            {
              "criteria": "cpe:2.3:a:gnu:gnutls:3.2.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BEC1076D-2249-406B-9D43-B24764BBE007"
            },
            {
              "criteria": "cpe:2.3:a:gnu:gnutls:3.2.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F039CD91-0FF6-4640-B981-20A3F9384A1C"
            },
            {
              "criteria": "cpe:2.3:a:gnu:gnutls:3.2.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8008DADD-DB6C-4C67-B333-0DC4C7152B2A"
            },
            {
              "criteria": "cpe:2.3:a:gnu:gnutls:3.2.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BC9E811B-4EED-4B6A-8836-5405F7F5A53D"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "secalert@redhat.com"
}