Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2014-3466

28
FAUCET Score

CVE-2014-3466 describes a buffer overflow vulnerability in the GnuTLS library, specifically within the read_server_hello function. This flaw affects GnuTLS versions before 3.1.25, 3.2.x before 3.2.15, and 3.3.x before 3.3.4. A remote malicious server can exploit this by sending a crafted ServerHello message with an excessively long session ID, leading to memory corruption, denial of service, or potentially arbitrary code execution on the client. The vulnerability carries a CVSS score of 6.8, indicating a medium severity. It can be exploited remotely with medium attack complexity and has potential impacts on confidentiality, integrity, and availability. The EPSS score is 0.13715, suggesting a low probability of exploitation in the wild. There is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Despite this, the vulnerability has garnered some community attention with two mentions and two media articles, indicating awareness within the cybersecurity community.

Impacted Technologies

VendorProductVersion(s)CPE
3.3.0CPE matchmatch criteria
cpe:2.3:a:gnu:gnutls:3.3.0:-:*:*:*:*:*:*
3.3.0CPE matchmatch criteria
cpe:2.3:a:gnu:gnutls:3.3.0:pre0:*:*:*:*:*:*
3.3.1CPE matchmatch criteria
cpe:2.3:a:gnu:gnutls:3.3.1:*:*:*:*:*:*:*
3.3.2CPE matchmatch criteria
cpe:2.3:a:gnu:gnutls:3.3.2:*:*:*:*:*:*:*
3.3.3CPE matchmatch criteria
cpe:2.3:a:gnu:gnutls:3.3.3:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

6.8MEDIUM

AV:N/AC:M/Au:N/C:P/I:P/A:P

Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
Access Vector
NETWORK
Access Complexity
MEDIUM
Authentication
NONE
Exploitability Score
8.6
Impact Score
6.4
CvssVersion
2.0

Exploit Intelligence

EPSS Score
11.22%
Probability of exploitation in next 30 days
EPSS Percentile
95.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.1122 is in the 95th percentile among its peer group of 19,958 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (6)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: gnutls-0:1.4.1-16.el5_10
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: gnutls-0:2.8.5-14.el6_5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: gnutls-0:3.1.18-9.el7_0
View patch
redhatpatch availablevia redhat_api
Product: RHEV 3.X Hypervisor and Agents for RHEL-6Fixed in: rhev-hypervisor6-0:6.5-20140624.0.el6ev
View patch
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 4Fixed in: gnutls
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: mingw32-gnutls

Vendor Advisories (1)

redhatCVE-2014-3466Important

gnutls: insufficient session id length check in _gnutls_read_server_hello (GNUTLS-SA-2014-3)

May 30, 2014

References

linux.oracle.com / errata/ELSA-2014-0594.html
linux.oracle.com / errata/ELSA-2014-0595.html
lists.opensuse.org / opensuse-security-announce/2014-06/msg00002.html
lists.opensuse.org / opensuse-security-announce/2014-06/msg00007.html
lists.opensuse.org / opensuse-security-announce/2014-06/msg00010.html
lists.opensuse.org / opensuse-security-announce/2014-06/msg00015.html
radare.today / technical-analysis-of-the-gnutls-hello-vulnerability
ExploitURL Repurposed
rhn.redhat.com / errata/RHSA-2014-0594.html
rhn.redhat.com / errata/RHSA-2014-0595.html
rhn.redhat.com / errata/RHSA-2014-0684.html
rhn.redhat.com / errata/RHSA-2014-0815.html
bugzilla.redhat.com / show_bug.cgi
secunia.com / advisories/58340
secunia.com / advisories/58598
secunia.com / advisories/58601
secunia.com / advisories/58642
secunia.com / advisories/59016
secunia.com / advisories/59021
secunia.com / advisories/59057
secunia.com / advisories/59086
secunia.com / advisories/59408
secunia.com / advisories/59838
secunia.com / advisories/60384
gitorious.org / gnutls/gnutls/commit/688ea6428a432c39203d00acd1af0e7684e5ddfd
ExploitPatch
www-01.ibm.com / support/docview.wss
www-947.ibm.com / support/entry/portal/docdisplay
debian.org / security/2014/dsa-2944
gnutls.org / security.html
Vendor Advisory
novell.com / support/kb/doc.php
novell.com / support/kb/doc.php
securityfocus.com / bid/67741
securitytracker.com / id/1030314
ubuntu.com / usn/USN-2229-1