CVE-2015-3308
published 2015-09-02CVE-2015-3308: Double free vulnerability in lib/x509/x509_ext.c in GnuTLS before 3.3.14 allows remote attackers to cause a denial of service or possibly have unspecified…
PriorityP433high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
3.92%
89.2th percentile
Double free vulnerability in lib/x509/x509_ext.c in GnuTLS before 3.3.14 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted CRL distribution point.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| debian | gnutls28 | < gnutls28 3.3.8-7 (bookworm) | gnutls28 3.3.8-7 (bookworm) |
| gnu | gnutls | <= 3.3.13 | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-f5vv-qq78-r728: Double free vulnerability in lib/x509/x509_ext
ghsa_unreviewed·2022-05-17
CVE-2015-3308 [HIGH] GHSA-f5vv-qq78-r728: Double free vulnerability in lib/x509/x509_ext
Double free vulnerability in lib/x509/x509_ext.c in GnuTLS before 3.3.14 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted CRL distribution point.
OSV
CVE-2015-3308: Double free vulnerability in lib/x509/x509_ext
osv·2015-09-02·CVSS 7.5
CVE-2015-3308 [HIGH] CVE-2015-3308: Double free vulnerability in lib/x509/x509_ext
Double free vulnerability in lib/x509/x509_ext.c in GnuTLS before 3.3.14 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted CRL distribution point.
Ubuntu
GnuTLS vulnerabilities
vendor_ubuntu·2015-09-01·CVSS 7.5
CVE-2015-3308 [HIGH] GnuTLS vulnerabilities
Title: GnuTLS vulnerabilities
Summary: GnuTLS could be made to crash or run programs if it processed a specially
crafted certificate.
It was discovered that GnuTLS incorrectly handled parsing CRL distribution
points. A remote attacker could possibly use this issue to cause a denial
of service, or execute arbitrary code. (CVE-2015-3308)
Kurt Roeckx discovered that GnuTLS incorrectly handled a long
DistinguishedName (DN) entry in a certificate. A remote attacker could
possibly use this issue to cause a denial of service, or execute arbitrary
code. (CVE-2015-6251)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
gnutls: use-after-free flaw in CRL distribution points parsing
vendor_redhat·2015-04-16·CVSS 7.5
CVE-2015-3308 [HIGH] CWE-416 gnutls: use-after-free flaw in CRL distribution points parsing
gnutls: use-after-free flaw in CRL distribution points parsing
Double free vulnerability in lib/x509/x509_ext.c in GnuTLS before 3.3.14 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted CRL distribution point.
Package: gnutls (Red Hat Enterprise Linux 5) - Not affected
Package: gnutls (Red Hat Enterprise Linux 6) - Not affected
Package: gnutls (Red Hat Enterprise Linux 7) - Will not fix
Package: mingw-virt-viewer (Red Hat Enterprise Virtualization 3) - Not affected
Debian
CVE-2015-3308: gnutls28 - Double free vulnerability in lib/x509/x509_ext.c in GnuTLS before 3.3.14 allows ...
vendor_debian·2015·CVSS 7.5
CVE-2015-3308 [HIGH] CVE-2015-3308: gnutls28 - Double free vulnerability in lib/x509/x509_ext.c in GnuTLS before 3.3.14 allows ...
Double free vulnerability in lib/x509/x509_ext.c in GnuTLS before 3.3.14 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted CRL distribution point.
Scope: local
bookworm: resolved (fixed in 3.3.8-7)
bullseye: resolved (fixed in 3.3.8-7)
forky: resolved (fixed in 3.3.8-7)
sid: resolved (fixed in 3.3.8-7)
trixie: resolved (fixed in 3.3.8-7)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-3308 gnutls: use-after-free flaw in CRL distribution points parsing
bugzilla·2015-04-16·CVSS 7.5
CVE-2015-3308 [HIGH] CVE-2015-3308 gnutls: use-after-free flaw in CRL distribution points parsing
CVE-2015-3308 gnutls: use-after-free flaw in CRL distribution points parsing
A use-after-free flaw was found in the way GnuTLS parsed CRL distribution points. A specially crafted certificate could cause an application using GnuTLS to crash.
Upstream patches:
https://gitlab.com/gnutls/gnutls/commit/d6972be33264ecc49a86cd0958209cd7363af1e9
https://gitlab.com/gnutls/gnutls/commit/053ae65403216acdb0a4e78b25ad66ee9f444f02
Discussion:
Created mingw-gnutls tracking bugs for this issue:
Affects: fedora-21 [bug 1212464]
Affects: epel-7 [bug 1212465]
---
Created gnutls tracking bugs for this issue:
Affects: fedora-21 [bug 1212463]
---
The affected function, gnutls_x509_ext_import_crl_dist_points(), was introduced in GnuTLS version 3.3.0:
http://gnutls.org/manual/html_node/X509-certificat
Bugzilla
CVE-2015-3308 gnutls: use-after-free flaw in CRL distribution points parsing [fedora-21]
bugzilla·2015-04-16·CVSS 7.5
CVE-2015-3308 [HIGH] CVE-2015-3308 gnutls: use-after-free flaw in CRL distribution points parsing [fedora-21]
CVE-2015-3308 gnutls: use-after-free flaw in CRL distribution points parsing [fedora-21]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
fedora-21 tracking bug for gnutls: see blocks
Bugzilla
CVE-2015-3308 mingw-gnutls: gnutls: use-after-free flaw in CRL distribution points parsing [fedora-21]
bugzilla·2015-04-16·CVSS 7.5
CVE-2015-3308 [HIGH] CVE-2015-3308 mingw-gnutls: gnutls: use-after-free flaw in CRL distribution points parsing [fedora-21]
CVE-2015-3308 mingw-gnutls: gnutls: use-after-free flaw in CRL distribution points parsing [fedora-21]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
fedora-21 tracking bug for ming
Bugzilla
CVE-2015-3308 mingw-gnutls: gnutls: use-after-free flaw in CRL distribution points parsing [epel-7]
bugzilla·2015-04-16·CVSS 7.5
CVE-2015-3308 [HIGH] CVE-2015-3308 mingw-gnutls: gnutls: use-after-free flaw in CRL distribution points parsing [epel-7]
CVE-2015-3308 mingw-gnutls: gnutls: use-after-free flaw in CRL distribution points parsing [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
epel-7 tracking bug for mingw
http://lists.fedoraproject.org/pipermail/package-announce/2015-April/155101.htmlhttp://www.gnutls.org/security.html#GNUTLS-SA-2015-4http://www.openwall.com/lists/oss-security/2015/04/15/6http://www.openwall.com/lists/oss-security/2015/04/16/6http://www.securityfocus.com/bid/74188http://www.securitytracker.com/id/1033774http://www.ubuntu.com/usn/USN-2727-1https://gitlab.com/gnutls/gnutls/commit/053ae65403216acdb0a4e78b25ad66ee9f444f02https://gitlab.com/gnutls/gnutls/commit/d6972be33264ecc49a86cd0958209cd7363af1e9https://security.gentoo.org/glsa/201506-03http://lists.fedoraproject.org/pipermail/package-announce/2015-April/155101.htmlhttp://www.gnutls.org/security.html#GNUTLS-SA-2015-4http://www.openwall.com/lists/oss-security/2015/04/15/6http://www.openwall.com/lists/oss-security/2015/04/16/6http://www.securityfocus.com/bid/74188http://www.securitytracker.com/id/1033774http://www.ubuntu.com/usn/USN-2727-1https://gitlab.com/gnutls/gnutls/commit/053ae65403216acdb0a4e78b25ad66ee9f444f02https://gitlab.com/gnutls/gnutls/commit/d6972be33264ecc49a86cd0958209cd7363af1e9https://security.gentoo.org/glsa/201506-03
2015-09-02
Published