CVE-2021-20231

Name
CVE-2021-20231
Description
A flaw was found in gnutls. A use after free issue in client sending key_share extension may lead to memory corruption and other consequences.
NVD Severity
high
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Issue Tracking https://bugzilla.redhat.com/show_bug.cgi?id=1922276
Exploit https://www.gnutls.org/security-new.html#GNUTLS-SA-2021-03-10
FEDORA https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OSLAE6PP33A7VYRYMYMUVB3U6B26GZER/
MLIST https://lists.apache.org/thread.html/r5f88bed447742fcc5c47bf1c7be965ef450131914a6e1f85feba2779@%3Cissues.spark.apache.org%3E
CONFIRM https://security.netapp.com/advisory/ntap-20210416-0005/
MLIST https://lists.apache.org/thread.html/rcd70a4c88a47a75fd2d5f3ffb7cee8c2a18c713320bd90fdcb57495f@%3Cissues.spark.apache.org%3E
MLIST https://lists.apache.org/thread.html/r5d4001031e7790d8c6396c499522b4ed2aab782da87b1a14184793bb@%3Cissues.spark.apache.org%3E
MLIST https://lists.apache.org/thread.html/r9cbc69e57276413788e90a6ee16c7c034ea4258d31935b70db2bd158@%3Cissues.spark.apache.org%3E
MLIST https://lists.apache.org/thread.html/rfd5273d72d244178441e6904a2f2b41a3268f569e8092ea0b3b2bb20@%3Cissues.spark.apache.org%3E
MLIST https://lists.apache.org/thread.html/rf5e1256d870193def4a82ad89ab95e63943a313b5ff0d81aa87e4532@%3Cissues.spark.apache.org%3E
MLIST https://lists.apache.org/thread.html/r50661d6f0082709aad9a584431b59ec364f9974b63b07e0800230168@%3Cissues.spark.apache.org%3E
MLIST https://lists.apache.org/thread.html/r6ac143ba6dd98bd4bf6bf010d46e56e254056459721ba18822d611f7@%3Cissues.spark.apache.org%3E

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:gnu:gnutls:*:*:*:*:*:*:*:* gnutls >= None < 3.7.1
cpe:2.3:a:gnu:gnutls:*:*:*:*:*:*:*:* gnutls >= 3.6.3 < 3.7.1

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
gnutls edge-main 3.7.1-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
gnutls edge-main 3.6.15-r0 None possibly vulnerable
gnutls edge-main 3.6.14-r0 None possibly vulnerable
gnutls edge-main 3.6.13-r0 None possibly vulnerable
gnutls edge-main 3.6.7-r0 None possibly vulnerable
gnutls edge-main 3.5.13-r0 None possibly vulnerable
gnutls 3.22-main 3.7.1-r0 None fixed
gnutls 3.22-main 3.6.15-r0 None possibly vulnerable
gnutls 3.22-main 3.6.14-r0 None possibly vulnerable
gnutls 3.22-main 3.6.13-r0 None possibly vulnerable
gnutls 3.22-main 3.6.7-r0 None possibly vulnerable
gnutls 3.22-main 3.5.13-r0 None possibly vulnerable
gnutls 3.21-main 3.7.1-r0 None fixed
gnutls 3.21-main 3.6.15-r0 None possibly vulnerable
gnutls 3.21-main 3.6.14-r0 None possibly vulnerable
gnutls 3.21-main 3.6.13-r0 None possibly vulnerable
gnutls 3.21-main 3.6.7-r0 None possibly vulnerable
gnutls 3.21-main 3.5.13-r0 None possibly vulnerable
gnutls 3.20-main 3.7.1-r0 None fixed
gnutls 3.20-main 3.6.15-r0 None possibly vulnerable
gnutls 3.20-main 3.6.14-r0 None possibly vulnerable
gnutls 3.20-main 3.6.13-r0 None possibly vulnerable
gnutls 3.20-main 3.6.7-r0 None possibly vulnerable
gnutls 3.20-main 3.5.13-r0 None possibly vulnerable
gnutls 3.19-main 3.7.1-r0 None fixed
gnutls 3.19-main 3.6.15-r0 None possibly vulnerable
gnutls 3.19-main 3.6.14-r0 None possibly vulnerable
gnutls 3.19-main 3.6.13-r0 None possibly vulnerable
gnutls 3.19-main 3.6.7-r0 None possibly vulnerable
gnutls 3.19-main 3.5.13-r0 None possibly vulnerable
gnutls 3.18-main 3.7.1-r0 None fixed
gnutls 3.17-main 3.7.1-r0 None fixed
gnutls 3.12-main 3.6.15-r1 Natanael Copa <ncopa@alpinelinux.org> fixed
gnutls 3.11-main 3.6.15-r1 Natanael Copa <ncopa@alpinelinux.org> fixed
gnutls 3.10-main 3.6.15-r1 Natanael Copa <ncopa@alpinelinux.org> fixed