CVE-2019-3829

Name
CVE-2019-3829
Description
A vulnerability was found in gnutls versions from 3.5.8 before 3.6.7. A memory corruption (double free) vulnerability in the certificate verification API. Any client or server application that verifies X.509 certificates with GnuTLS 3.5.8 or later is affected.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Exploit https://www.gnutls.org/security-new.html#GNUTLS-SA-2019-03-27
Exploit https://gitlab.com/gnutls/gnutls/issues/694
Issue Tracking https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3829
FEDORA https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WRSOL66LHP4SD3Y2ECJDOGT4K663ECDU/
FEDORA https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/L7TJIBRJWGWSH6XIO2MXIQ3W6ES4R6I4/
FEDORA https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/A3ETBUFBB4G7AITAOUYPGXVMBGVXKUAN/
GENTOO https://security.gentoo.org/glsa/201904-14
SUSE http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00017.html
UBUNTU https://usn.ubuntu.com/3999-1/
CONFIRM https://security.netapp.com/advisory/ntap-20190619-0004/
REDHAT https://access.redhat.com/errata/RHSA-2019:3600

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:gnu:gnutls:*:*:*:*:*:*:*:* gnutls >= 3.5.8 < 3.6.7

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
gnutls edge-main 3.6.7-r0 None fixed
gnutls edge-main 3.5.13-r0 None possibly vulnerable
gnutls 3.22-main 3.6.7-r0 None fixed
gnutls 3.22-main 3.5.13-r0 None possibly vulnerable
gnutls 3.21-main 3.6.7-r0 None fixed
gnutls 3.21-main 3.5.13-r0 None possibly vulnerable
gnutls 3.20-main 3.6.7-r0 None fixed
gnutls 3.20-main 3.5.13-r0 None possibly vulnerable
gnutls 3.19-main 3.6.7-r0 None fixed
gnutls 3.19-main 3.5.13-r0 None possibly vulnerable
gnutls 3.18-main 3.6.7-r0 None fixed
gnutls 3.17-main 3.6.7-r0 None fixed
gnutls 3.12-main 3.6.7-r0 None fixed
gnutls 3.11-main 3.6.7-r0 None fixed
gnutls 3.10-main 3.6.7-r0 None fixed