CVE-2021-4209
24.08.2022, 16:15
A NULL pointer dereference flaw was found in GnuTLS. As Nettle's hash update functions internally call memcpy, providing zero-length input may cause undefined behavior. This flaw leads to a denial of service after authentication in rare circumstances.Enginsight
| Vendor | Product | Version |
|---|---|---|
| gnu | gnutls | 𝑥 < 3.7.3 |
| redhat | enterprise_linux | 8.0 |
| netapp | active_iq_unified_manager | - |
| netapp | solidfire_\&_hci_management_node | - |
| netapp | hci_bootstrap_os | - |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| gnutls26 |
| ||||||||||||||||||||||||||||||
| gnutls28 |
|
Common Weakness Enumeration
References