GnuTLS
cpe:2.3:a:gnu:gnutls:*:*:*:*:*:*:*
- < 10
- < 7
- < 8
- < 9
- < 4
A memory corruption vulnerability allowing information disclosure has been identified in libgnutls. This issue arises when a remote attacker sends an extremely short premaster secret during an RSA key exchange to a server using an RSA key backed by a PKCS#11 token. The manipulation can trigger a short heap overread, leading to unauthorized memory access.
Exploitation of this vulnerability causes a heap overread, allowing a remote attacker to read sensitive information from memory.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.