CVE

Id
94264  
CVE No.
CVE-2016-7444  
Status
Candidate  
Description
The gnutls_ocsp_resp_check_crt function in lib/x509/ocsp.c in GnuTLS before 3.4.15 and 3.5.x before 3.5.4 does not verify the serial length of an OCSP response, which might allow remote attackers to bypass an intended certificate validation mechanism via vectors involving trailing bytes left by gnutls_malloc.  
Phase
Assigned (20160909)  
Votes
None (candidate not yet proposed)  
Comments