CVE-2005-1431 describes a denial-of-service vulnerability in GnuTLS versions 1.2.x prior to 1.2.3 and 1.0.x prior to 1.0.25, stemming from improper "record packet parsing" likely involving padding bytes. This vulnerability carries a CVSS score of 5.0 (AV:N/AC:L/Au:N/C:N/I:N/A:P), indicating it can be exploited remotely with low complexity by unauthenticated attackers to cause a partial denial of service. There is no evidence of active exploitation, publicly available exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion beyond a single mention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0.18CPE matchmatch criteria | cpe:2.3:a:gnu:gnutls:1.0.18:*:*:*:*:*:*:* | ||
1.0.19CPE matchmatch criteria | cpe:2.3:a:gnu:gnutls:1.0.19:*:*:*:*:*:*:* | ||
1.0.20CPE matchmatch criteria | cpe:2.3:a:gnu:gnutls:1.0.20:*:*:*:*:*:*:* | ||
1.0.21CPE matchmatch criteria | cpe:2.3:a:gnu:gnutls:1.0.21:*:*:*:*:*:*:* | ||
1.0.22CPE matchmatch criteria | cpe:2.3:a:gnu:gnutls:1.0.22:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.