CVE-2019-3829
MEDIUMGnuTLS 3.5.8-3.6.6 - Memory Corruption via Certificate Verification API
Title source: llmDescription
A vulnerability was found in gnutls versions from 3.5.8 before 3.6.7. A memory corruption (double free) vulnerability in the certificate verification API. Any client or server application that verifies X.509 certificates with GnuTLS 3.5.8 or later is affected.
References (11)
Core 11
Core References
Exploit, Patch, Vendor Advisory x_refsource_misc
https://www.gnutls.org/security-new.html#GNUTLS-SA-2019-03-27
Issue Tracking, Third Party Advisory x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3829
Exploit, Patch, Third Party Advisory x_refsource_confirm
https://gitlab.com/gnutls/gnutls/issues/694
Mailing List, Third Party Advisory vendor-advisory
x_refsource_fedora
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WRSOL66LHP4SD3Y2ECJDOGT4K663ECDU/
Mailing List, Third Party Advisory vendor-advisory
x_refsource_fedora
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/L7TJIBRJWGWSH6XIO2MXIQ3W6ES4R6I4/
Mailing List, Third Party Advisory vendor-advisory
x_refsource_fedora
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/A3ETBUFBB4G7AITAOUYPGXVMBGVXKUAN/
Third Party Advisory vendor-advisory
x_refsource_gentoo
https://security.gentoo.org/glsa/201904-14
Mailing List vendor-advisory
x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00017.html
Vendor Advisory vendor-advisory
x_refsource_ubuntu
https://usn.ubuntu.com/3999-1/
Vendor Advisory x_refsource_confirm
https://security.netapp.com/advisory/ntap-20190619-0004/
Vendor Advisory vendor-advisory
x_refsource_redhat
https://access.redhat.com/errata/RHSA-2019:3600
Scores
CVSS v3
5.3
EPSS
0.0208
EPSS Percentile
84.2%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Details
CWE
CWE-415
CWE-416
Status
published
Products (2)
fedoraproject/fedora
gnu/gnutls
3.5.8 - 3.6.7
Published
Mar 27, 2019
Tracked Since
Feb 18, 2026