Oval Definition:oval:org.opensuse.security:def:20100731
Revision Date:2012-08-30Version:1
Title:CVE-2010-0731
Description:

The gnutls_x509_crt_get_serial function in the GnuTLS library before 1.2.1, when running on big-endian, 64-bit platforms, calls the asn1_read_value with a pointer to the wrong data type and the wrong length value, which allows remote attackers to bypass the certificate revocation list (CRL) check and cause a stack-based buffer overflow via a crafted X.509 certificate, related to extraction of a serial number.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2010-0731
Platform(s):SUSE CORE 9 for AMD64 and Intel EM64T
SUSE CORE 9 for IBM zSeries 64bit
Product(s):
Definition Synopsis
  • core9 is installed
  • AND Package Information
  • gnutls-devel less than 1.0.8-26.23
  • OR gnutls less than 1.0.8-26.23
  • BACK