Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-2509

Опубликовано: 29 июл. 2022
Источник: redhat
CVSS3: 7.5

Описание

A vulnerability found in gnutls. This security flaw happens because of a double free error occurs during verification of pkcs7 signatures in gnutls_pkcs7_verify function.

A vulnerability was found in gnutls. This issue is due to a double-free error that occurs during the verification of pkcs7 signatures in the gnutls_pkcs7_verify function.

Отчет

This flaw is rated as moderate because the flaw is more difficult to exploit but could still lead to some compromise of the availability of resources under certain circumstances. This is the type of vulnerability that could have had an important impact but is less easily exploited based on a technical evaluation of the flaw, and affect unlikely configurations.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6gnutlsNot affected
Red Hat Enterprise Linux 7gnutlsOut of support scope
Red Hat Enterprise Linux 8gnutlsFixedRHSA-2022:710525.10.2022
Red Hat Enterprise Linux 8gnutlsFixedRHSA-2022:710525.10.2022
Red Hat Enterprise Linux 9gnutlsFixedRHSA-2022:685411.10.2022
Red Hat Enterprise Linux 9gnutlsFixedRHSA-2022:685411.10.2022

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=2108977gnutls: Double free during gnutls_pkcs7_verify

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 3 года назад

A vulnerability found in gnutls. This security flaw happens because of a double free error occurs during verification of pkcs7 signatures in gnutls_pkcs7_verify function.

CVSS3: 7.5
nvd
почти 3 года назад

A vulnerability found in gnutls. This security flaw happens because of a double free error occurs during verification of pkcs7 signatures in gnutls_pkcs7_verify function.

CVSS3: 7.5
msrc
почти 3 года назад

Описание отсутствует

CVSS3: 7.5
debian
почти 3 года назад

A vulnerability found in gnutls. This security flaw happens because of ...

suse-cvrf
почти 3 года назад

Security update for gnutls

7.5 High

CVSS3