7.5
CVSSv2

CVE-2015-3308

Published: 02/09/2015 Updated: 22/12/2016
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Double free vulnerability in lib/x509/x509_ext.c in GnuTLS prior to 3.3.14 allows remote malicious users to cause a denial of service or possibly have unspecified other impact via a crafted CRL distribution point.

Vulnerable Product Search on Vulmon Subscribe to Product

gnu gnutls

canonical ubuntu linux 15.04

Vendor Advisories

Debian Bug report logs - #782776 gnutls28: CVE-2015-3308: use-after-free flaw in CRL distribution points parsing Package: src:gnutls28; Maintainer for src:gnutls28 is Debian GnuTLS Maintainers <pkg-gnutls-maint@listsaliothdebianorg>; Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Fri, 17 Apr 2015 17:09:02 U ...
GnuTLS could be made to crash or run programs if it processed a specially crafted certificate ...
Double free vulnerability in lib/x509/x509_extc in GnuTLS before 3314 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted CRL distribution point ...