PT-2019-4465 · Gnu+5 · Gnutls+5
Published
2019-02-18
·
Updated
2024-06-15
·
CVE-2019-3836
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
gnutls versions 3.6.3 through 3.6.6
Description
The issue is related to an uninitialized pointer access in the gnutls library, which can be triggered by certain post-handshake messages, potentially allowing a remote attacker to cause a denial of service when receiving asynchronous messages.
Recommendations
For gnutls versions 3.6.3 through 3.6.6, update to version 3.6.7 or later to resolve the issue.
Exploit
Fix
Access of Uninitialized Pointer
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Centos
Red Hat
Suse
Ubuntu
Gnutls