CVE-2019-3836

Severity CVSS v4.0:
Pending analysis
Type:
CWE-824 Access of Uninitialized Pointer
Publication date:
01/04/2019
Last modified:
07/11/2023

Description

It was discovered in gnutls before version 3.6.7 upstream that there is an uninitialized pointer access in gnutls versions 3.6.3 or later which can be triggered by certain post-handshake messages.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:gnu:gnutls:*:*:*:*:*:*:*:* 3.6.3 (including) 3.6.7 (excluding)
cpe:2.3:o:fedoraproject:fedora:28:*:*:*:*:*:*:*
cpe:2.3:o:opensuse:leap:15.0:*:*:*:*:*:*:*