CVE-2014-3466 describes a buffer overflow vulnerability in the GnuTLS library, specifically within the read_server_hello function. This flaw affects GnuTLS versions before 3.1.25, 3.2.x before 3.2.15, and 3.3.x before 3.3.4. A remote malicious server can exploit this by sending a crafted ServerHello message with an excessively long session ID, leading to memory corruption, denial of service, or potentially arbitrary code execution on the client. The vulnerability carries a CVSS score of 6.8, indicating a medium severity. It can be exploited remotely with medium attack complexity and has potential impacts on confidentiality, integrity, and availability. The EPSS score is 0.13715, suggesting a low probability of exploitation in the wild. There is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Despite this, the vulnerability has garnered some community attention with two mentions and two media articles, indicating awareness within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.3.0CPE matchmatch criteria | cpe:2.3:a:gnu:gnutls:3.3.0:-:*:*:*:*:*:* | ||
3.3.0CPE matchmatch criteria | cpe:2.3:a:gnu:gnutls:3.3.0:pre0:*:*:*:*:*:* | ||
3.3.1CPE matchmatch criteria | cpe:2.3:a:gnu:gnutls:3.3.1:*:*:*:*:*:*:* | ||
3.3.2CPE matchmatch criteria | cpe:2.3:a:gnu:gnutls:3.3.2:*:*:*:*:*:*:* | ||
3.3.3CPE matchmatch criteria | cpe:2.3:a:gnu:gnutls:3.3.3:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.