GnuTLS
cpe:2.3:a:gnu:gnutls:*:*:*:*:*:*:*
- <= 3.8.8
A denial-of-service vulnerability has been identified in GnuTLS, which relies on libtasn1 for processing ASN.1 data. The issue arises from an inefficient algorithm in libtasn1 that can cause excessive delays when decoding certain DER-encoded certificate data. This flaw allows remote attackers to send specially crafted certificates that consume significant resources, making GnuTLS unresponsive or slow.
Exploitation of this vulnerability leads to a denial-of-service condition, causing GnuTLS to become unresponsive or slow, and increasing resource consumption.
The vulnerability can be reproduced by using the 'certtool' command-line utility included with GnuTLS. A crafted certificate that exploits the vulnerability should be saved as 'cert.pem'. When 'certtool' is run with this file, the CPU usage will spike to 100%, demonstrating the denial-of-service effect.
Users can upgrade to GnuTLS versions 3.8.9 or later, where this vulnerability has been fixed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.