CVE-2014-3466: GNU Gnutls
Medium severity, CVSS 6.8. EPSS: 11.2% chance of exploitation in the next 30 days.
Buffer overflow in the read_server_hello function in lib/gnutls_handshake.c in GnuTLS before 3.1.25, 3.2.x before 3.2.15, and 3.3.x before 3.3.4 allows remote servers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a long session id in a ServerHello message.
Affected products
- GNU Gnutls: version 3.3.0 only; version 3.3.1 only; version 3.3.2 only; version 3.3.3 only; up to and including 3.1.24; version 3.1.0 only; …
Published 2014-06-03. Last modified 2026-06-17.