Multiple heap-based buffer overflows in the read_attribute function in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allow remote attackers to have unspecified impact via a crafted OpenPGP certificate.
{ "vanir_signatures": [ { "id": "CVE-2017-5337-17caa5a1", "digest": { "length": 1221.0, "function_hash": "34316826050325807286257102503133027334" }, "signature_type": "Function", "target": { "file": "lib/opencdk/read-packet.c", "function": "read_attribute" }, "deprecated": false, "signature_version": "v1", "source": "https://gitlab.com/gnutls/gnutls@94fcf1645ea17223237aaf8d19132e004afddc1a" }, { "id": "CVE-2017-5337-2d2b89e8", "digest": { "line_hashes": [ "155854010347857455929637180497948167649", "129826789405367421266673420226055203432", "85619286324533141014977893827304376546", "43460310134364866870336876598770311694", "103696513081154491635951662116019124472", "36562559203923717243070322186774955885", "104803504453980401914426414084749863029", "263668351692199783737246135007796435838", "233518112391343654507650639339066015488", "224908140920710801821669837437840641513", "123325277111586797667413770654112908445", "142808787265784835326519161014312124161", "205270665860039296394282494908470876592", "217798603298426714915125044238156905403", "54585905776301594915369957147639303497", "312608799009702900848524824449325619157", "131908739653057702324864006699870620055", "100904059689255290252073749712219041178", "261027178440775222684962619189307445458", "172846092304523496738584916977883367388", "329946323999842406853121444995955007998", "155765693883445006227153407311359077193", "286138277281671229534890957030444519072", "219630002001039515136696635413466307476", "71417650207818203308056053528499458743", "274357801457805551029378982574274880769", "91555177254400981999589871323277743395", "187894839585079895863654723688686775397", "317388249487147175905803090669749166997", "92482746881640266734323517228148780129", "82712562824336227400401060452140644989", "154984291061868285071029139344859519064", "273332125035542316030059607738078609700", "246248504322481078017806571502797101131", "334034405076537999037516634451095565180", "308572316954035808055712414512381330742", "286445900054720561907490305293670518518", "295257275005228754391686652687262666635", "266675769579695579387374957192776015877", "211438260322472824424898828293262899350", "85535847345663056570588441446946122063" ], "threshold": 0.9 }, "signature_type": "Line", "target": { "file": "lib/opencdk/read-packet.c" }, "deprecated": false, "signature_version": "v1", "source": "https://gitlab.com/gnutls/gnutls@94fcf1645ea17223237aaf8d19132e004afddc1a" } ] }