5
CVSSv2

CVE-2019-3829

Published: 27/03/2019 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

A vulnerability was found in gnutls versions from 3.5.8 prior to 3.6.7. A memory corruption (double free) vulnerability in the certificate verification API. Any client or server application that verifies X.509 certificates with GnuTLS 3.5.8 or later is affected.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

gnu gnutls

fedoraproject fedora -

Vendor Advisories

Synopsis Moderate: gnutls security, bug fix, and enhancement update Type/Severity Security Advisory: Moderate Topic An update for gnutls is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring Syst ...
Several security issues were fixed in GnuTLS ...
A critical memory corruption vulnerability has been found in GnuTLS versions prior to 367, in any API backed by verify_crt(), including gnutls_x509_trust_list_verify_crt() and related routines Any client or server that verifies X509 certificates with GnuTLS is likely affected and can be compromised by a malicious server or active network attack ...