CVE-2017-7507 PUBLISHED

GnuTLS version 3.5.12 and earlier is vulnerable to a NULL pointer dereference while decoding a status response TLS extension with valid contents. This could lead to a crash of the GnuTLS server application.

EPSS 0.52% · 66.5th percentile

Risk Scores

EPSS Score
0.52%
66.5th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSgnutls280, 3.3.15-5ubuntu2, 3.3.18-1ubuntu1

Timeline

References

Open in Interactive Console →