CVE-2019-3836

MEDIUM

GnuTLS >=3.6.3 - Memory Corruption

Title source: llm
STIX 2.1

Description

It was discovered in gnutls before version 3.6.7 upstream that there is an uninitialized pointer access in gnutls versions 3.6.3 or later which can be triggered by certain post-handshake messages.

Scores

CVSS v3 5.9
EPSS 0.0036
EPSS Percentile 58.3%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-456 CWE-824
Status published
Products (3)
fedoraproject/fedora 28
gnu/gnutls 3.6.3 - 3.6.7
opensuse/leap 15.0
Published Apr 01, 2019
Tracked Since Feb 18, 2026