Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-3829

Опубликовано: 27 мар. 2019
Источник: nvd
CVSS3: 5.3
CVSS3: 7.5
CVSS2: 5
EPSS Низкий

Описание

A vulnerability was found in gnutls versions from 3.5.8 before 3.6.7. A memory corruption (double free) vulnerability in the certificate verification API. Any client or server application that verifies X.509 certificates with GnuTLS 3.5.8 or later is affected.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:gnu:gnutls:*:*:*:*:*:*:*:*
Версия от 3.5.8 (включая) до 3.6.7 (исключая)
Конфигурация 2
cpe:2.3:o:fedoraproject:fedora:-:*:*:*:*:*:*:*

EPSS

Процентиль: 84%
0.02082
Низкий

5.3 Medium

CVSS3

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-416
CWE-415

Связанные уязвимости

CVSS3: 5.3
ubuntu
почти 7 лет назад

A vulnerability was found in gnutls versions from 3.5.8 before 3.6.7. A memory corruption (double free) vulnerability in the certificate verification API. Any client or server application that verifies X.509 certificates with GnuTLS 3.5.8 or later is affected.

CVSS3: 5.3
redhat
почти 7 лет назад

A vulnerability was found in gnutls versions from 3.5.8 before 3.6.7. A memory corruption (double free) vulnerability in the certificate verification API. Any client or server application that verifies X.509 certificates with GnuTLS 3.5.8 or later is affected.

CVSS3: 5.3
debian
почти 7 лет назад

A vulnerability was found in gnutls versions from 3.5.8 before 3.6.7. ...

CVSS3: 7.5
github
больше 3 лет назад

A vulnerability was found in gnutls versions from 3.5.8 before 3.6.7. A memory corruption (double free) vulnerability in the certificate verification API. Any client or server application that verifies X.509 certificates with GnuTLS 3.5.8 or later is affected.

CVSS3: 7.5
fstec
почти 7 лет назад

Уязвимость криптографической библиотеки GnuTLS, связанная с повторным освобождением памяти, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 84%
0.02082
Низкий

5.3 Medium

CVSS3

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-416
CWE-415