Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-3836

Опубликовано: 01 апр. 2019
Источник: nvd
CVSS3: 5.9
CVSS3: 7.5
CVSS2: 5
EPSS Низкий

Описание

It was discovered in gnutls before version 3.6.7 upstream that there is an uninitialized pointer access in gnutls versions 3.6.3 or later which can be triggered by certain post-handshake messages.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:gnu:gnutls:*:*:*:*:*:*:*:*
Версия от 3.6.3 (включая) до 3.6.7 (исключая)
Конфигурация 2
cpe:2.3:o:fedoraproject:fedora:28:*:*:*:*:*:*:*
Конфигурация 3
cpe:2.3:o:opensuse:leap:15.0:*:*:*:*:*:*:*

EPSS

Процентиль: 58%
0.00362
Низкий

5.9 Medium

CVSS3

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-456
CWE-824

Связанные уязвимости

CVSS3: 5.9
ubuntu
почти 7 лет назад

It was discovered in gnutls before version 3.6.7 upstream that there is an uninitialized pointer access in gnutls versions 3.6.3 or later which can be triggered by certain post-handshake messages.

CVSS3: 5.9
redhat
почти 7 лет назад

It was discovered in gnutls before version 3.6.7 upstream that there is an uninitialized pointer access in gnutls versions 3.6.3 or later which can be triggered by certain post-handshake messages.

CVSS3: 5.9
debian
почти 7 лет назад

It was discovered in gnutls before version 3.6.7 upstream that there i ...

CVSS3: 7.5
github
больше 3 лет назад

It was discovered in gnutls before version 3.6.7 upstream that there is an uninitialized pointer access in gnutls versions 3.6.3 or later which can be triggered by certain post-handshake messages.

CVSS3: 5.9
fstec
почти 7 лет назад

Уязвимость криптографической библиотеки GnuTLS, связанная с доступом к неинициализированному указателю, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 58%
0.00362
Низкий

5.9 Medium

CVSS3

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-456
CWE-824