CVE-2014-8564
Publication date 10 November 2014
Last updated 24 July 2024
Ubuntu priority
The _gnutls_ecc_ansi_x963_export function in gnutls_ecc.c in GnuTLS 3.x before 3.1.28, 3.2.x before 3.2.20, and 3.3.x before 3.3.10 allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted (1) Elliptic Curve Cryptography (ECC) certificate or (2) certificate signing requests (CSR), related to generating key IDs.
Status
Package | Ubuntu Release | Status |
---|---|---|
gnutls26 | ||
18.04 LTS bionic | Not in release | |
16.04 LTS xenial | Not in release | |
14.04 LTS trusty |
Not affected
|
|
gnutls28 | ||
18.04 LTS bionic |
Fixed 3.3.8-3ubuntu2
|
|
16.04 LTS xenial |
Fixed 3.3.8-3ubuntu2
|
|
14.04 LTS trusty | Not in release | |
Patch details
Package | Patch details |
---|---|
gnutls28 |
References
Related Ubuntu Security Notices (USN)
- USN-2403-1
- GnuTLS vulnerability
- 11 November 2014