A NULL pointer dereference flaw was found in GnuTLS. As Nettle's hash update functions internally call memcpy, providing zero-length input may cause undefined behavior. This flaw leads to a denial of service after authentication in rare circumstances.
2022-08-24T16:15:09.927
2024-11-21T06:37:09.190
Modified
CVSSv3.1: 6.5 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | gnu | gnutls | < 3.7.3 | Yes |
Operating System | redhat | enterprise_linux | 8.0 | Yes |
Application | netapp | active_iq_unified_manager | - | Yes |
Application | netapp | solidfire_\&_hci_management_node | - | Yes |
Application | netapp | hci_bootstrap_os | - | Yes |
Hardware | netapp | hci_compute_node | - | No |