7.5
CVSSv2

CVE-2017-5334

Published: 24/03/2017 Updated: 30/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Double free vulnerability in the gnutls_x509_ext_import_proxy function in GnuTLS prior to 3.3.26 and 3.5.x prior to 3.5.8 allows remote malicious users to have unspecified impact via crafted policy language information in an X.509 certificate with a Proxy Certificate Information extension.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

opensuse leap 42.1

opensuse leap 42.2

gnu gnutls 3.5.3

gnu gnutls 3.5.4

gnu gnutls 3.5.5

gnu gnutls 3.5.6

gnu gnutls 3.5.1

gnu gnutls 3.5.2

gnu gnutls

gnu gnutls 3.5.7

gnu gnutls 3.5.0

Vendor Advisories

Synopsis Moderate: gnutls security, bug fix, and enhancement update Type/Severity Security Advisory: Moderate Topic An update for gnutls is now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring Syst ...
GnuTLS could be made to hang if it received specially crafted network traffic ...
Several security issues were fixed in GnuTLS ...