CVE-2019-3829

MEDIUM

Gnutls < 3.6.7 - Use After Free

Title source: rule

Description

A vulnerability was found in gnutls versions from 3.5.8 before 3.6.7. A memory corruption (double free) vulnerability in the certificate verification API. Any client or server application that verifies X.509 certificates with GnuTLS 3.5.8 or later is affected.

Scores

CVSS v3 5.3
EPSS 0.0208
EPSS Percentile 83.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Classification

CWE
CWE-415 CWE-416
Status published

Affected Products (2)

gnu/gnutls < 3.6.7
fedoraproject/fedora

Timeline

Published Mar 27, 2019
Tracked Since Feb 18, 2026