CVE-2017-7869 is a heap-based buffer overflow vulnerability in GnuTLS versions prior to 3.5.10, specifically within the cdk_pkt_read function, stemming from an integer overflow. This vulnerability carries a CVSS v3 score of 7.5 (High), indicating it can be exploited remotely with low attack complexity, potentially leading to a denial of service. While no public exploit code or Metasploit modules are available, the vulnerability has received some community discussion and media coverage, though it is not listed on the KEV catalog as actively exploited.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 3.5.9CPE matchmatch criteria | cpe:2.3:a:gnu:gnutls:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.