An issue was discovered in GnuTLS before 3.6.15. A server...
Moderate severity
Unreviewed
Published
May 24, 2022
to the GitHub Advisory Database
•
Updated Feb 27, 2023
Description
Published by the National Vulnerability Database
Sep 4, 2020
Published to the GitHub Advisory Database
May 24, 2022
Last updated
Feb 27, 2023
An issue was discovered in GnuTLS before 3.6.15. A server can trigger a NULL pointer dereference in a TLS 1.3 client if a no_renegotiation alert is sent with unexpected timing, and then an invalid second handshake occurs. The crash happens in the application's error handling path, where the gnutls_deinit function is called after detecting a handshake failure.
References