RULE(RULE ID:711222)

Rule General Information
Release Date: 2017-08-31
Rule Name: GnuTLS status_request Extension Null Pointer Dereference Vulnerability(CVE-2017-7507)
Severity:
CVE ID:
Rule Protection Details
Description: GnuTLS version 3.5.12 and earlier is vulnerable to a NULL pointer dereference while decoding a status response TLS extension with valid contents. The vulnerability is due to improper parsing of certain values in the status_request extension.us ECDH ciphersuites. This could lead to a crash of the GnuTLS server application.
Impact: An attacker can launch a denial of service attack by exploiting the vulnerability successfully.
Affected OS: Solaris, Other Unix, FreeBSD, Linux
Reference: CVE-2017-7507
Solutions
Update vendor's patch.