Unrated severityNVD Advisory· Published Jun 3, 2014· Updated May 6, 2026
CVE-2014-3466
CVE-2014-3466
Description
Buffer overflow in the read_server_hello function in lib/gnutls_handshake.c in GnuTLS before 3.1.25, 3.2.x before 3.2.15, and 3.3.x before 3.3.4 allows remote servers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a long session id in a ServerHello message.
Affected products
48cpe:2.3:a:gnu:gnutls:*:*:*:*:*:*:*:*+ 46 more
- cpe:2.3:a:gnu:gnutls:*:*:*:*:*:*:*:*range: <=3.1.24
- cpe:2.3:a:gnu:gnutls:3.1.0:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:gnutls:3.1.1:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:gnutls:3.1.10:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:gnutls:3.1.11:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:gnutls:3.1.12:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:gnutls:3.1.13:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:gnutls:3.1.14:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:gnutls:3.1.15:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:gnutls:3.1.16:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:gnutls:3.1.17:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:gnutls:3.1.18:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:gnutls:3.1.19:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:gnutls:3.1.2:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:gnutls:3.1.20:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:gnutls:3.1.21:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:gnutls:3.1.22:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:gnutls:3.1.23:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:gnutls:3.1.3:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:gnutls:3.1.4:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:gnutls:3.1.5:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:gnutls:3.1.6:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:gnutls:3.1.7:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:gnutls:3.1.8:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:gnutls:3.1.9:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:gnutls:3.2.0:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:gnutls:3.2.1:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:gnutls:3.2.10:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:gnutls:3.2.11:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:gnutls:3.2.12:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:gnutls:3.2.12.1:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:gnutls:3.2.13:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:gnutls:3.2.14:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:gnutls:3.2.2:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:gnutls:3.2.3:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:gnutls:3.2.4:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:gnutls:3.2.5:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:gnutls:3.2.6:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:gnutls:3.2.7:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:gnutls:3.2.8:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:gnutls:3.2.8.1:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:gnutls:3.2.9:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:gnutls:3.3.0:-:*:*:*:*:*:*
- cpe:2.3:a:gnu:gnutls:3.3.0:pre0:*:*:*:*:*:*
- cpe:2.3:a:gnu:gnutls:3.3.1:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:gnutls:3.3.2:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:gnutls:3.3.3:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
33- radare.today/technical-analysis-of-the-gnutls-hello-vulnerability/nvdExploitURL Repurposed
- www.gitorious.org/gnutls/gnutls/commit/688ea6428a432c39203d00acd1af0e7684e5ddfdnvdExploitPatch
- www.gnutls.org/security.htmlnvdVendor Advisory
- linux.oracle.com/errata/ELSA-2014-0594.htmlnvd
- linux.oracle.com/errata/ELSA-2014-0595.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2014-06/msg00002.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2014-06/msg00007.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2014-06/msg00010.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2014-06/msg00015.htmlnvd
- rhn.redhat.com/errata/RHSA-2014-0594.htmlnvd
- rhn.redhat.com/errata/RHSA-2014-0595.htmlnvd
- rhn.redhat.com/errata/RHSA-2014-0684.htmlnvd
- rhn.redhat.com/errata/RHSA-2014-0815.htmlnvd
- secunia.com/advisories/58340nvd
- secunia.com/advisories/58598nvd
- secunia.com/advisories/58601nvd
- secunia.com/advisories/58642nvd
- secunia.com/advisories/59016nvd
- secunia.com/advisories/59021nvd
- secunia.com/advisories/59057nvd
- secunia.com/advisories/59086nvd
- secunia.com/advisories/59408nvd
- secunia.com/advisories/59838nvd
- secunia.com/advisories/60384nvd
- www-01.ibm.com/support/docview.wssnvd
- www-947.ibm.com/support/entry/portal/docdisplaynvd
- www.debian.org/security/2014/dsa-2944nvd
- www.novell.com/support/kb/doc.phpnvd
- www.novell.com/support/kb/doc.phpnvd
- www.securityfocus.com/bid/67741nvd
- www.securitytracker.com/id/1030314nvd
- www.ubuntu.com/usn/USN-2229-1nvd
- bugzilla.redhat.com/show_bug.cginvd
News mentions
0No linked articles in our index yet.