{"id":"DEBIAN-CVE-2012-1573","details":"gnutls_cipher.c in libgnutls in GnuTLS before 2.12.17 and 3.x before 3.0.15 does not properly handle data encrypted with a block cipher, which allows remote attackers to cause a denial of service (heap memory corruption and application crash) via a crafted record, as demonstrated by a crafted GenericBlockCipher structure.","modified":"2026-04-28T20:11:48.240736Z","published":"2012-03-26T19:55:01.390Z","upstream":["CVE-2012-1573"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2012-1573"}],"affected":[{"package":{"name":"gnutls28","ecosystem":"Debian:11","purl":"pkg:deb/debian/gnutls28?arch=source"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.0.17-2"}]}],"ecosystem_specific":{"urgency":"high"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2012-1573.json"}},{"package":{"name":"gnutls28","ecosystem":"Debian:12","purl":"pkg:deb/debian/gnutls28?arch=source"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.0.17-2"}]}],"ecosystem_specific":{"urgency":"high"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2012-1573.json"}},{"package":{"name":"gnutls28","ecosystem":"Debian:13","purl":"pkg:deb/debian/gnutls28?arch=source"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.0.17-2"}]}],"ecosystem_specific":{"urgency":"high"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2012-1573.json"}},{"package":{"name":"gnutls28","ecosystem":"Debian:14","purl":"pkg:deb/debian/gnutls28?arch=source"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.0.17-2"}]}],"ecosystem_specific":{"urgency":"high"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2012-1573.json"}}],"schema_version":"1.7.5"}