CVE-2021-20232: Use After Free
A flaw was found in gnutls. A use after free issue in clientsendparams in lib/ext/presharedkey.c may lead to memory corruption and other potential consequences.
Other sources
GnuTLS is vulnerable to a denial of service, caused by a use-after-free issue in clientsendparams in lib/ext/presharedkey.c. By sending a specially-crafted request, an attacker could exploit this vulnerability to cause memory corruption and other consequences.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-20232?
CVE-2021-20232 is a vulnerability in GnuTLS that could allow an attacker to cause a denial of service by exploiting a use-after-free issue in client_send_params in lib/ext/pre_shared_key.c.
How does CVE-2021-20232 impact GnuTLS?
CVE-2021-20232 could lead to memory corruption and other consequences, potentially resulting in a denial of service.
What is the severity of CVE-2021-20232?
CVE-2021-20232 has a severity rating of 7.4, which is considered high.
How can I fix CVE-2021-20232 in IBM QRadar SIEM version 7.5.0 GA?
To fix CVE-2021-20232 in IBM QRadar SIEM version 7.5.0 GA, you should apply the patch available at the following URL: [Patch URL]
How can I fix CVE-2021-20232 in IBM QRadar SIEM version 7.4.3 GA - 7.4.3 FP4?
To fix CVE-2021-20232 in IBM QRadar SIEM version 7.4.3 GA - 7.4.3 FP4, you should apply the patch available at the following URL: [Patch URL]
How can I fix CVE-2021-20232 in IBM QRadar SIEM version 7.3.3 GA - 7.3.3 FP10?
To fix CVE-2021-20232 in IBM QRadar SIEM version 7.3.3 GA - 7.3.3 FP10, you should apply the patch available at the following URL: [Patch URL]