Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-3836

Опубликовано: 27 мар. 2019
Источник: redhat
CVSS3: 5.9

Описание

It was discovered in gnutls before version 3.6.7 upstream that there is an uninitialized pointer access in gnutls versions 3.6.3 or later which can be triggered by certain post-handshake messages.

A flaw was found in the way gnutls handled malformed TLS 1.3 asynchronous messages. An attacker could use this flaw to crash an application compiled with gnutls via invalid pointer access.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5gnutlsNot affected
Red Hat Enterprise Linux 6gnutlsNot affected
Red Hat Enterprise Linux 7gnutlsNot affected
Red Hat Enterprise Linux 8gnutlsFixedRHSA-2019:360005.11.2019
Red Hat Enterprise Linux 8gnutlsFixedRHSA-2019:360005.11.2019

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-456
https://bugzilla.redhat.com/show_bug.cgi?id=1678411gnutls: invalid pointer access upon receiving async handshake messages

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.9
ubuntu
почти 7 лет назад

It was discovered in gnutls before version 3.6.7 upstream that there is an uninitialized pointer access in gnutls versions 3.6.3 or later which can be triggered by certain post-handshake messages.

CVSS3: 5.9
nvd
почти 7 лет назад

It was discovered in gnutls before version 3.6.7 upstream that there is an uninitialized pointer access in gnutls versions 3.6.3 or later which can be triggered by certain post-handshake messages.

CVSS3: 5.9
debian
почти 7 лет назад

It was discovered in gnutls before version 3.6.7 upstream that there i ...

CVSS3: 7.5
github
больше 3 лет назад

It was discovered in gnutls before version 3.6.7 upstream that there is an uninitialized pointer access in gnutls versions 3.6.3 or later which can be triggered by certain post-handshake messages.

CVSS3: 5.9
fstec
почти 7 лет назад

Уязвимость криптографической библиотеки GnuTLS, связанная с доступом к неинициализированному указателю, позволяющая нарушителю вызвать отказ в обслуживании

5.9 Medium

CVSS3