CVE-2019-3836

MEDIUM

gnutls 3.6.3-3.6.6 - Denial of Service via Post-Handshake Message Handling

Title source: llm
STIX 2.1

Description

It was discovered in gnutls before version 3.6.7 upstream that there is an uninitialized pointer access in gnutls versions 3.6.3 or later which can be triggered by certain post-handshake messages.

References (8)

Core 8
Core References
Issue Tracking, Third Party Advisory x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3836
Exploit, Issue Tracking, Third Party Advisory x_refsource_confirm
https://gitlab.com/gnutls/gnutls/issues/704
Third Party Advisory vendor-advisory x_refsource_gentoo
https://security.gentoo.org/glsa/201904-14
Third Party Advisory x_refsource_confirm
https://security.netapp.com/advisory/ntap-20190502-0005/
Mailing List, Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00017.html
Vendor Advisory vendor-advisory x_refsource_ubuntu
https://usn.ubuntu.com/3999-1/
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2019:3600

Scores

CVSS v3 5.9
EPSS 0.0340
EPSS Percentile 87.3%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-456 CWE-824
Status published
Products (3)
fedoraproject/fedora 28
gnu/gnutls 3.6.3 - 3.6.7
opensuse/leap 15.0
Published Apr 01, 2019
Tracked Since Feb 18, 2026