Double free vulnerability in libgnutls in GnuTLS before 3.0.14 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted certificate list.
CVSS Details
- CVSS 3.1 Base Score: 7.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade gnutls28 | Jul 30, 2024 | Mar 13, 2012 |
| Suse | — | Upgrade gnutls-debuginfoUpgrade libgnutls-openssl27Upgrade libgnutls28-x86Upgrade libgnutls-openssl-develUpgrade libgnutlsxx-develUpgrade libgnutlsxx28Upgrade libgnutls28-debuginfo-32bitUpgrade libgnutls28-debuginfo-x86Upgrade gnutls-debugsourceUpgrade libgnutls-extra28-debuginfoUpgrade libgnutls-openssl27-debuginfoUpgrade libgnutls-devel-32bitUpgrade libgnutls-develUpgrade gnutlsUpgrade libgnutls28-32bitUpgrade libgnutls-extra28Upgrade libgnutls-extra-develUpgrade libgnutlsxx28-debuginfoUpgrade libgnutls28-debuginfoUpgrade libgnutls28 | Dec 12, 2013 | Mar 13, 2012 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub