Double free vulnerability in libgnutls in GnuTLS before 3.0.14 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted certificate list.
CVSS Details
- CVSS 3.1 Base Score: 7.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade gnutls28 | Jul 30, 2024 | Mar 13, 2012 |
| Suse | — | Upgrade libgnutls-develUpgrade libgnutls28Upgrade libgnutls28-32bitUpgrade libgnutls-extra28Upgrade libgnutls-extra-develUpgrade gnutlsUpgrade libgnutls28-debuginfoUpgrade libgnutlsxx28-debuginfoUpgrade libgnutls28-x86Upgrade libgnutlsxx-develUpgrade libgnutls-openssl-develUpgrade libgnutlsxx28Upgrade gnutls-debuginfoUpgrade libgnutls-extra28-debuginfoUpgrade gnutls-debugsourceUpgrade libgnutls-openssl27Upgrade libgnutls28-debuginfo-x86Upgrade libgnutls-openssl27-debuginfoUpgrade libgnutls28-debuginfo-32bitUpgrade libgnutls-devel-32bit | Dec 12, 2013 | Mar 13, 2012 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub