Double free vulnerability in lib/x509/x509_ext.c in GnuTLS before 3.3.14 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted CRL distribution point.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade gnutls | Aug 30, 2017 | Sep 2, 2015 |
| Debian | — | Upgrade gnutls28 | Jul 30, 2024 | Sep 2, 2015 |
| Gentoo Linux | — | Upgrade net-libs/gnutls. | Oct 30, 2017 | Sep 2, 2015 |
| Huawei Euleros 2_0_sp2 | — | Upgrade gnutlsUpgrade gnutls-develUpgrade gnutls-c++Upgrade gnutls-utilsUpgrade gnutls-dane | Dec 4, 2019 | Sep 2, 2015 |
| Huawei Euleros 2_0_sp3 | — | Upgrade gnutls-daneUpgrade gnutlsUpgrade gnutls-utilsUpgrade gnutls-develUpgrade gnutls-c++ | Dec 18, 2019 | Sep 2, 2015 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Apr 16, 2015 |
| Ubuntu | — | Upgrade libgnutls-deb0-28 | Nov 8, 2024 | Sep 2, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub