MGASA-2013-0354

Source
https://advisories.mageia.org/MGASA-2013-0354.html
Import Source
https://advisories.mageia.org/MGASA-2013-0354.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2013-0354
Upstream
  • CVE-2013-4466
Published
2013-11-30T21:17:13Z
Modified
2026-04-16T06:26:07Z
Summary
Updated gnutls package fixes security vulnerability
Details

A DNS server that returns more 4 DANE entries could corrupt the memory of a requesting client using the DANE library from GnuTLS before 3.1.15 and 3.2.5 (CVE-2013-4466).

This updates GnuTLS to version 3.1.16, fixing this issue and several other bugs

References
Credits

Affected packages

Mageia:3 / gnutls

Package

Name
gnutls
Purl
pkg:rpm/mageia/gnutls?arch=source&distro=mageia-3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.1.16-1.mga3

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2013-0354.json"