RULE(RULE ID:711148)

Rule General Information
Release Date: 2017-05-10
Rule Name: Gnutls Proxy Certificate Information Extension Memory Corruption Vulnerability (CVE-2017-5334)
Severity:
CVE ID:
Rule Protection Details
Description: Double free vulnerability in the gnutls_x509_ext_import_proxy function in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allows remote attackers to have unspecified impact via crafted policy language information in an X.509 certificate with a Proxy Certificate Information extension.
Impact: An attacker can execute arbitrary code in the context of the vulnerable system. Failed exploit may cause denial-of-service attack.
Affected OS: Windows, Other Unix, FreeBSD, Linux
Reference: SecurityFocusBID:95370
SecurityTrackerID:1037576
Solutions
More advisories have been published on the website, please visit for more suggestions:
http://gnutls.org/security.html#GNUTLS-SA-2017-1