CVE-2019-3829
published 2019-03-27CVE-2019-3829: A vulnerability was found in gnutls versions from 3.5.8 before 3.6.7. A memory corruption (double free) vulnerability in the certificate verification API. Any…
PriorityP358high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
58.97%
99.0th percentile
A vulnerability was found in gnutls versions from 3.5.8 before 3.6.7. A memory corruption (double free) vulnerability in the certificate verification API. Any client or server application that verifies X.509 certificates with GnuTLS 3.5.8 or later is affected.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | gnutls28 | < gnutls28 3.6.7-2 (bookworm) | gnutls28 3.6.7-2 (bookworm) |
| gnu | gnutls | >= 3.5.8 < 3.6.7 | 3.6.7 |
| gnutls | gnutls | — | — |
| gnutls | gnutls | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →The vulnerable code path is in `_gnutls_x509_get_signature`, which does not clear `signature->data` in the cleanup path — monitor for crashes or double-free signals in processes calling GnuTLS certificate verification routines (versions 3.5.8 through 3.6.6). ↗
- →Trigger vector is a specially-crafted X.509 certificate sent to any client or server application that calls GnuTLS certificate verification; look for anomalous or malformed certificate chains in TLS handshake traffic. ↗
- →Affected version range is GnuTLS 3.5.8 up to (not including) 3.6.7; inventory and flag any deployments running these versions. ↗
- ·Red Hat Enterprise Linux 5, 6, and 7 ship GnuTLS versions predating 3.5.8 and are NOT affected; only RHEL 8 required patching. ↗
- ·The double-free manifests differently depending on threading model: use-after-free in multi-threaded clients vs. double-free in single-threaded clients. ↗
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_ubuntu5.9MEDIUM
vendor_debian5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mm54-95hq-f739: A vulnerability was found in gnutls versions from 3
ghsa_unreviewed·2022-05-14
CVE-2019-3829 [HIGH] CWE-415 GHSA-mm54-95hq-f739: A vulnerability was found in gnutls versions from 3
A vulnerability was found in gnutls versions from 3.5.8 before 3.6.7. A memory corruption (double free) vulnerability in the certificate verification API. Any client or server application that verifies X.509 certificates with GnuTLS 3.5.8 or later is affected.
OSV
gnutls28 vulnerabilities
osv·2019-05-30·CVSS 5.9
CVE-2018-10844 [MEDIUM] gnutls28 vulnerabilities
gnutls28 vulnerabilities
Eyal Ronen, Kenneth G. Paterson, and Adi Shamir discovered that GnuTLS was
vulnerable to a timing side-channel attack known as the "Lucky Thirteen"
issue. A remote attacker could possibly use this issue to perform
plaintext-recovery attacks via analysis of timing data. This issue only
affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2018-10844,
CVE-2018-10845, CVE-2018-10846)
Tavis Ormandy discovered that GnuTLS incorrectly handled memory when
verifying certain X.509 certificates. A remote attacker could use this
issue to cause GnuTLS to crash, resulting in a denial of service, or
possibly execute arbitrary code. This issue only affected Ubuntu 18.04 LTS,
Ubuntu 18.10, and Ubuntu 19.04. (CVE-2019-3829)
It was discovered that GnuTLS incorrectly handled certai
OSV
CVE-2019-3829: A vulnerability was found in gnutls versions from 3
osv·2019-03-27·CVSS 7.5
CVE-2019-3829 [HIGH] CVE-2019-3829: A vulnerability was found in gnutls versions from 3
A vulnerability was found in gnutls versions from 3.5.8 before 3.6.7. A memory corruption (double free) vulnerability in the certificate verification API. Any client or server application that verifies X.509 certificates with GnuTLS 3.5.8 or later is affected.
Ubuntu
GnuTLS vulnerabilities
vendor_ubuntu·2019-05-30·CVSS 5.9
CVE-2018-10844 [MEDIUM] GnuTLS vulnerabilities
Title: GnuTLS vulnerabilities
Summary: Several security issues were fixed in GnuTLS.
Eyal Ronen, Kenneth G. Paterson, and Adi Shamir discovered that GnuTLS was
vulnerable to a timing side-channel attack known as the "Lucky Thirteen"
issue. A remote attacker could possibly use this issue to perform
plaintext-recovery attacks via analysis of timing data. This issue only
affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2018-10844,
CVE-2018-10845, CVE-2018-10846)
Tavis Ormandy discovered that GnuTLS incorrectly handled memory when
verifying certain X.509 certificates. A remote attacker could use this
issue to cause GnuTLS to crash, resulting in a denial of service, or
possibly execute arbitrary code. This issue only affected Ubuntu 18.04 LTS,
Ubuntu 18.10, and Ubuntu 19.04. (CVE-2019-38
Red Hat
gnutls: use-after-free/double-free in certificate verification
vendor_redhat·2019-03-27·CVSS 5.3
CVE-2019-3829 [MEDIUM] CWE-416 gnutls: use-after-free/double-free in certificate verification
gnutls: use-after-free/double-free in certificate verification
A vulnerability was found in gnutls versions from 3.5.8 before 3.6.7. A memory corruption (double free) vulnerability in the certificate verification API. Any client or server application that verifies X.509 certificates with GnuTLS 3.5.8 or later is affected.
A double free flaw was found in the way the certificate verification API was implemented for gnutls. An attacker could cause a client or server application compiled against gnutls to crash by parsing a specially-crafted certificate.
Package: gnutls (Red Hat Enterprise Linux 5) - Not affected
Package: gnutls (Red Hat Enterprise Linux 6) - Not affected
Package: gnutls (Red Hat Enterprise Linux 7) - Not affected
Package: gnutls (Red Hat OpenShift Enterprise 3) - Not af
Debian
CVE-2019-3829: gnutls28 - A vulnerability was found in gnutls versions from 3.5.8 before 3.6.7. A memory c...
vendor_debian·2019·CVSS 5.3
CVE-2019-3829 [MEDIUM] CVE-2019-3829: gnutls28 - A vulnerability was found in gnutls versions from 3.5.8 before 3.6.7. A memory c...
A vulnerability was found in gnutls versions from 3.5.8 before 3.6.7. A memory corruption (double free) vulnerability in the certificate verification API. Any client or server application that verifies X.509 certificates with GnuTLS 3.5.8 or later is affected.
Scope: local
bookworm: resolved (fixed in 3.6.7-2)
bullseye: resolved (fixed in 3.6.7-2)
forky: resolved (fixed in 3.6.7-2)
sid: resolved (fixed in 3.6.7-2)
trixie: resolved (fixed in 3.6.7-2)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-18466 podman: resolving symlink in host filesystem leads to unexpected results of copy operation
bugzilla·2019-08-22·CVSS 5.5
CVE-2019-18466 [MEDIUM] CVE-2019-18466 podman: resolving symlink in host filesystem leads to unexpected results of copy operation
CVE-2019-18466 podman: resolving symlink in host filesystem leads to unexpected results of copy operation
'podman cp' will resolve a carefully crafted symlink in host-filesystem space, yielding unexpected results when cp'ing from container to host. An attacker could create a container image containing particular symlinks that, when copied by a victim user to the host filesystem, may overwrite existing files with others from the host.
Upstream Issue:
https://github.com/containers/libpod/issues/3829
Discussion:
This is a duplicate of this issue https://bugzilla.redhat.com/show_bug.cgi?id=1741709
---
Upstream patch:
https://github.com/containers/libpod/commit/5c09c4d2947a759724f9d5aef6bac04317e03f7e
---
Created podman tracking bugs for this issue:
Affects: fedora-all [bug 1754354]
-
Bugzilla
CVE-2019-3829 gnutls: use-after-free/double-free in certificate verification [fedora-all]
bugzilla·2019-03-27·CVSS 5.3
CVE-2019-3829 [MEDIUM] CVE-2019-3829 gnutls: use-after-free/double-free in certificate verification [fedora-all]
CVE-2019-3829 gnutls: use-after-free/double-free in certificate verification [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple suppor
Bugzilla
CVE-2019-3829 mingw-gnutls: gnutls: use-after-free/double-free in certificate verification [fedora-all]
bugzilla·2019-03-27·CVSS 5.3
CVE-2019-3829 [MEDIUM] CVE-2019-3829 mingw-gnutls: gnutls: use-after-free/double-free in certificate verification [fedora-all]
CVE-2019-3829 mingw-gnutls: gnutls: use-after-free/double-free in certificate verification [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects m
Bugzilla
CVE-2019-3829 gnutls: use-after-free/double-free in certificate verification
bugzilla·2019-02-13·CVSS 5.3
CVE-2019-3829 [MEDIUM] CVE-2019-3829 gnutls: use-after-free/double-free in certificate verification
CVE-2019-3829 gnutls: use-after-free/double-free in certificate verification
A flaw was found in gnutls 3.5.8 or later. A use-after-free in multi-threaded-clients and a double-free vulnerability in single-threaded clients because _gnutls_x509_get_signature does not clear signature->data in the cleanup path.
Upstream bug:
https://gitlab.com/gnutls/gnutls/issues/694
Discussion:
Acknowledgments:
Name: Tavis Ormandy (Google Project Zero)
---
Created gnutls tracking bugs for this issue:
Affects: fedora-all [bug 1693210]
Created mingw-gnutls tracking bugs for this issue:
Affects: fedora-all [bug 1693211]
---
External References:
https://www.gnutls.org/security-new.html#GNUTLS-SA-2019-03-27
---
Upstream patch: https://gitlab.com/gnutls/gnutls/commit/ad27713bef613e6c4600a0fb83ae48
http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00017.htmlhttps://access.redhat.com/errata/RHSA-2019:3600https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3829https://gitlab.com/gnutls/gnutls/issues/694https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/A3ETBUFBB4G7AITAOUYPGXVMBGVXKUAN/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/L7TJIBRJWGWSH6XIO2MXIQ3W6ES4R6I4/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WRSOL66LHP4SD3Y2ECJDOGT4K663ECDU/https://security.gentoo.org/glsa/201904-14https://security.netapp.com/advisory/ntap-20190619-0004/https://usn.ubuntu.com/3999-1/https://www.gnutls.org/security-new.html#GNUTLS-SA-2019-03-27http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00017.htmlhttps://access.redhat.com/errata/RHSA-2019:3600https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3829https://gitlab.com/gnutls/gnutls/issues/694https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/A3ETBUFBB4G7AITAOUYPGXVMBGVXKUAN/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/L7TJIBRJWGWSH6XIO2MXIQ3W6ES4R6I4/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WRSOL66LHP4SD3Y2ECJDOGT4K663ECDU/https://security.gentoo.org/glsa/201904-14https://security.netapp.com/advisory/ntap-20190619-0004/https://usn.ubuntu.com/3999-1/https://www.gnutls.org/security-new.html#GNUTLS-SA-2019-03-27
2019-03-27
Published