CVE-2011-4128 describes a buffer overflow vulnerability in the gnutls_session_get_data function within GnuTLS versions 2.12.x before 2.12.14 and 3.x before 3.0.7. This flaw allows a malicious TLS server to trigger a denial of service (application crash) on a client performing nonstandard session resumption by sending an oversized SessionTicket. The vulnerability has a CVSS score of 4.3, indicating a medium attack complexity and a potential impact of partial availability, with no confidentiality or integrity impact. There is no evidence of active exploitation, nor are there any public exploit modules available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage are minimal, suggesting low overall attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.12.0CPE matchmatch criteria | cpe:2.3:a:gnu:gnutls:2.12.0:*:*:*:*:*:*:* | ||
2.12.1CPE matchmatch criteria | cpe:2.3:a:gnu:gnutls:2.12.1:*:*:*:*:*:*:* | ||
2.12.2CPE matchmatch criteria | cpe:2.3:a:gnu:gnutls:2.12.2:*:*:*:*:*:*:* | ||
2.12.3CPE matchmatch criteria | cpe:2.3:a:gnu:gnutls:2.12.3:*:*:*:*:*:*:* | ||
2.12.4CPE matchmatch criteria | cpe:2.3:a:gnu:gnutls:2.12.4:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:N/I:N/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.