HomeinetAfter Heartbleed, comes the GnuTLS bug CVE-2014-3466

After Heartbleed, comes the GnuTLS bug CVE-2014-3466

GnuTLS It is open source and was found to be vulnerable to a buffer overflow vulnerability that could be exploited to crash TLS clients or potentially execute malicious code on the systems it runs on.

security GnuTLS

The GnuTLS library implements the secure sockets layer (SSL) and transport layer security (TLS) protocols on computers and servers to provide encrypted communication over insecure channels.

The bug, CVE-2014-3466, was discovered by Joonas Kuorilehto of security firm Codenomicon, the same security firm that discovered the Internet's biggest vulnerability, Heartbleed. Unlike Heartbleed, the GnuTLS library is not as widely used as OpenSSL.

The GnuTLS vulnerability lies in the way GnuTLS parses the session ID from the server response at the beginning of a TLS communication. It does not check the length of the session ID in the ServerHello message, and allows a malicious server to send an excessively long value in order to perform a buffer overflow.

Red Hat has already analyzed the vulnerability and issued a patch. For more technical details, read here.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS