CVE Database
/

CVE-2021-4209

Back to search

CVE-2021-4209

Published: Aug 24, 2022

Modified: Aug 3, 2024

PUBLISHED

Description

A NULL pointer dereference flaw was found in GnuTLS. As Nettle's hash update functions internally call memcpy, providing zero-length input may cause undefined behavior. This flaw leads to a denial of service after authentication in rare circumstances.

VendorProductVersions

n/a

GnuTLS

affected
Fixed in gnutls v3.7.3

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now