Another major security vulnerability has been discovered in the popular GnuTLS encryption library that leaves Linux vulnerable to remote code execution.
GnuTLS is a free library implementation of the Secure Socket Layer (SSL), Transport Layer Security (TLS), and Datagram Transport Layer Security (dtls) protocols used to provide secure communications.
A malicious server could exploit this vulnerability by sending a very long Session ID and executing malicious code on “a TLS/SSL client connection, using GnuTLS.”.
📧
Subscribe to the SecNews Newsletter

