Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-3836

Опубликовано: 01 апр. 2019
Источник: debian

Описание

It was discovered in gnutls before version 3.6.7 upstream that there is an uninitialized pointer access in gnutls versions 3.6.3 or later which can be triggered by certain post-handshake messages.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
gnutls28fixed3.6.7-1experimentalpackage
gnutls28fixed3.6.7-2package
gnutls28not-affectedstretchpackage
gnutls28not-affectedjessiepackage

Примечания

  • https://bugzilla.redhat.com/show_bug.cgi?id=1678411

  • https://gitlab.com/gnutls/gnutls/issues/704

  • https://gitlab.com/gnutls/gnutls/commit/96e07075e8f105b13e76b11e493d5aa2dd937226

  • https://www.gnutls.org/security-new.html#GNUTLS-SA-2019-03-27

  • Upstream versions affected are 3.6.4 and later before 3.6.7

Связанные уязвимости

CVSS3: 5.9
ubuntu
почти 7 лет назад

It was discovered in gnutls before version 3.6.7 upstream that there is an uninitialized pointer access in gnutls versions 3.6.3 or later which can be triggered by certain post-handshake messages.

CVSS3: 5.9
redhat
почти 7 лет назад

It was discovered in gnutls before version 3.6.7 upstream that there is an uninitialized pointer access in gnutls versions 3.6.3 or later which can be triggered by certain post-handshake messages.

CVSS3: 5.9
nvd
почти 7 лет назад

It was discovered in gnutls before version 3.6.7 upstream that there is an uninitialized pointer access in gnutls versions 3.6.3 or later which can be triggered by certain post-handshake messages.

CVSS3: 7.5
github
больше 3 лет назад

It was discovered in gnutls before version 3.6.7 upstream that there is an uninitialized pointer access in gnutls versions 3.6.3 or later which can be triggered by certain post-handshake messages.

CVSS3: 5.9
fstec
почти 7 лет назад

Уязвимость криптографической библиотеки GnuTLS, связанная с доступом к неинициализированному указателю, позволяющая нарушителю вызвать отказ в обслуживании