CVE-2017-5337 describes multiple heap-based buffer overflows in the read_attribute function of GnuTLS versions prior to 3.3.26 and 3.5.8, impacting products like GNU GnuTLS and OpenSUSE. This critical vulnerability (CVSS 9.8) allows remote attackers to achieve high confidentiality, integrity, and availability impact with low attack complexity, requiring no user interaction. While no public exploit code (Metasploit, Nuclei, ExploitDB) is available and it's not in CISA's KEV catalog, the vulnerability has garnered some community discussion and media coverage, indicating awareness despite its inactive status on the Hot List.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
42.1CPE matchmatch criteria | cpe:2.3:o:opensuse:leap:42.1:*:*:*:*:*:*:* | ||
42.2CPE matchmatch criteria | cpe:2.3:o:opensuse:leap:42.2:*:*:*:*:*:*:* | ||
<= 3.3.25CPE matchmatch criteria | cpe:2.3:a:gnu:gnutls:*:*:*:*:*:*:*:* | ||
3.5.0CPE matchmatch criteria | cpe:2.3:a:gnu:gnutls:3.5.0:*:*:*:*:*:*:* | ||
3.5.1CPE matchmatch criteria | cpe:2.3:a:gnu:gnutls:3.5.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.