CVE-2019-3829

A vulnerability was found in gnutls versions from 3.5.8 before 3.6.7. A memory corruption (double free) vulnerability in the certificate verification API. Any client or server application that verifies X.509 certificates with GnuTLS 3.5.8 or later is affected.
References
Link Resource
http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00017.html
https://access.redhat.com/errata/RHSA-2019:3600
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3829 Issue Tracking Third Party Advisory
https://gitlab.com/gnutls/gnutls/issues/694 Exploit Patch Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/A3ETBUFBB4G7AITAOUYPGXVMBGVXKUAN/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/L7TJIBRJWGWSH6XIO2MXIQ3W6ES4R6I4/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WRSOL66LHP4SD3Y2ECJDOGT4K663ECDU/
https://security.gentoo.org/glsa/201904-14
https://security.netapp.com/advisory/ntap-20190619-0004/
https://usn.ubuntu.com/3999-1/
https://www.gnutls.org/security-new.html#GNUTLS-SA-2019-03-27 Exploit Patch Vendor Advisory
http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00017.html
https://access.redhat.com/errata/RHSA-2019:3600
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3829 Issue Tracking Third Party Advisory
https://gitlab.com/gnutls/gnutls/issues/694 Exploit Patch Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/A3ETBUFBB4G7AITAOUYPGXVMBGVXKUAN/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/L7TJIBRJWGWSH6XIO2MXIQ3W6ES4R6I4/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WRSOL66LHP4SD3Y2ECJDOGT4K663ECDU/
https://security.gentoo.org/glsa/201904-14
https://security.netapp.com/advisory/ntap-20190619-0004/
https://usn.ubuntu.com/3999-1/
https://www.gnutls.org/security-new.html#GNUTLS-SA-2019-03-27 Exploit Patch Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:gnu:gnutls:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:fedoraproject:fedora:-:*:*:*:*:*:*:*

History

21 Nov 2024, 04:42

Type Values Removed Values Added
References () http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00017.html - () http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00017.html -
References () https://access.redhat.com/errata/RHSA-2019:3600 - () https://access.redhat.com/errata/RHSA-2019:3600 -
References () https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3829 - Issue Tracking, Third Party Advisory () https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3829 - Issue Tracking, Third Party Advisory
References () https://gitlab.com/gnutls/gnutls/issues/694 - Exploit, Patch, Third Party Advisory () https://gitlab.com/gnutls/gnutls/issues/694 - Exploit, Patch, Third Party Advisory
References () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/A3ETBUFBB4G7AITAOUYPGXVMBGVXKUAN/ - () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/A3ETBUFBB4G7AITAOUYPGXVMBGVXKUAN/ -
References () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/L7TJIBRJWGWSH6XIO2MXIQ3W6ES4R6I4/ - () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/L7TJIBRJWGWSH6XIO2MXIQ3W6ES4R6I4/ -
References () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WRSOL66LHP4SD3Y2ECJDOGT4K663ECDU/ - () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WRSOL66LHP4SD3Y2ECJDOGT4K663ECDU/ -
References () https://security.gentoo.org/glsa/201904-14 - () https://security.gentoo.org/glsa/201904-14 -
References () https://security.netapp.com/advisory/ntap-20190619-0004/ - () https://security.netapp.com/advisory/ntap-20190619-0004/ -
References () https://usn.ubuntu.com/3999-1/ - () https://usn.ubuntu.com/3999-1/ -
References () https://www.gnutls.org/security-new.html#GNUTLS-SA-2019-03-27 - Exploit, Patch, Vendor Advisory () https://www.gnutls.org/security-new.html#GNUTLS-SA-2019-03-27 - Exploit, Patch, Vendor Advisory
CVSS v2 : 5.0
v3 : 7.5
v2 : 5.0
v3 : 5.3

Information

Published : 2019-03-27 18:29

Updated : 2024-11-21 04:42


NVD link : CVE-2019-3829

Mitre link : CVE-2019-3829

CVE.ORG link : CVE-2019-3829


JSON object : View

Products Affected

fedoraproject

  • fedora

gnu

  • gnutls
CWE
CWE-416

Use After Free

CWE-415

Double Free