CVE-2019-3829
MEDIUMGnutls < 3.6.7 - Use After Free
Title source: ruleDescription
A vulnerability was found in gnutls versions from 3.5.8 before 3.6.7. A memory corruption (double free) vulnerability in the certificate verification API. Any client or server application that verifies X.509 certificates with GnuTLS 3.5.8 or later is affected.
References (11)
Scores
CVSS v3
5.3
EPSS
0.0208
EPSS Percentile
83.8%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Classification
CWE
CWE-415
CWE-416
Status
published
Affected Products (2)
gnu/gnutls
< 3.6.7
fedoraproject/fedora
Timeline
Published
Mar 27, 2019
Tracked Since
Feb 18, 2026