CVE-2013-2116: GNU Gnutls

Medium severity, CVSS 5.0. EPSS: 3.8% chance of exploitation in the next 30 days.

The _gnutls_ciphertext2compressed function in lib/gnutls_cipher.c in GnuTLS 2.12.23 allows remote attackers to cause a denial of service (buffer over-read and crash) via a crafted padding length. NOTE: this might be due to an incorrect fix for CVE-2013-0169.

Affected products

  • GNU Gnutls: version 2.12.23 only

Published 2013-07-03. Last modified 2026-06-16.