Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-3836

Опубликовано: 27 мар. 2019
Источник: redhat
CVSS3: 5.9
EPSS Низкий

Описание

It was discovered in gnutls before version 3.6.7 upstream that there is an uninitialized pointer access in gnutls versions 3.6.3 or later which can be triggered by certain post-handshake messages.

A flaw was found in the way gnutls handled malformed TLS 1.3 asynchronous messages. An attacker could use this flaw to crash an application compiled with gnutls via invalid pointer access.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5gnutlsNot affected
Red Hat Enterprise Linux 6gnutlsNot affected
Red Hat Enterprise Linux 7gnutlsNot affected
Red Hat Enterprise Linux 8gnutlsFixedRHSA-2019:360005.11.2019
Red Hat Enterprise Linux 8gnutlsFixedRHSA-2019:360005.11.2019

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-456
https://bugzilla.redhat.com/show_bug.cgi?id=1678411gnutls: invalid pointer access upon receiving async handshake messages

EPSS

Процентиль: 88%
0.03401
Низкий

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.9
ubuntu
больше 7 лет назад

It was discovered in gnutls before version 3.6.7 upstream that there is an uninitialized pointer access in gnutls versions 3.6.3 or later which can be triggered by certain post-handshake messages.

CVSS3: 5.9
nvd
больше 7 лет назад

It was discovered in gnutls before version 3.6.7 upstream that there is an uninitialized pointer access in gnutls versions 3.6.3 or later which can be triggered by certain post-handshake messages.

CVSS3: 5.9
debian
больше 7 лет назад

It was discovered in gnutls before version 3.6.7 upstream that there i ...

CVSS3: 7.5
github
около 4 лет назад

It was discovered in gnutls before version 3.6.7 upstream that there is an uninitialized pointer access in gnutls versions 3.6.3 or later which can be triggered by certain post-handshake messages.

CVSS3: 5.9
fstec
больше 7 лет назад

Уязвимость криптографической библиотеки GnuTLS, связанная с доступом к неинициализированному указателю, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 88%
0.03401
Низкий

5.9 Medium

CVSS3