CVE-2019-3836
published 2019-04-01CVE-2019-3836: It was discovered in gnutls before version 3.6.7 upstream that there is an uninitialized pointer access in gnutls versions 3.6.3 or later which can be…
PriorityP338high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
3.40%
87.5th percentile
It was discovered in gnutls before version 3.6.7 upstream that there is an uninitialized pointer access in gnutls versions 3.6.3 or later which can be triggered by certain post-handshake messages.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | gnutls28 | < gnutls28 3.6.7-2 (bookworm) | gnutls28 3.6.7-2 (bookworm) |
| fedoraproject | fedora | — | — |
| gnu | gnutls | >= 3.6.3 < 3.6.7 | 3.6.7 |
| gnutls | gnutls | — | — |
| opensuse | leap | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian5.9MEDIUM
vendor_redhat5.9MEDIUM
vendor_ubuntu5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-fqw6-7w7w-627p: It was discovered in gnutls before version 3
ghsa_unreviewed·2022-05-14
CVE-2019-3836 [HIGH] CWE-824 GHSA-fqw6-7w7w-627p: It was discovered in gnutls before version 3
It was discovered in gnutls before version 3.6.7 upstream that there is an uninitialized pointer access in gnutls versions 3.6.3 or later which can be triggered by certain post-handshake messages.
OSV
gnutls28 vulnerabilities
osv·2019-05-30·CVSS 5.9
CVE-2018-10844 [MEDIUM] gnutls28 vulnerabilities
gnutls28 vulnerabilities
Eyal Ronen, Kenneth G. Paterson, and Adi Shamir discovered that GnuTLS was
vulnerable to a timing side-channel attack known as the "Lucky Thirteen"
issue. A remote attacker could possibly use this issue to perform
plaintext-recovery attacks via analysis of timing data. This issue only
affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2018-10844,
CVE-2018-10845, CVE-2018-10846)
Tavis Ormandy discovered that GnuTLS incorrectly handled memory when
verifying certain X.509 certificates. A remote attacker could use this
issue to cause GnuTLS to crash, resulting in a denial of service, or
possibly execute arbitrary code. This issue only affected Ubuntu 18.04 LTS,
Ubuntu 18.10, and Ubuntu 19.04. (CVE-2019-3829)
It was discovered that GnuTLS incorrectly handled certai
OSV
CVE-2019-3836: It was discovered in gnutls before version 3
osv·2019-04-01·CVSS 7.5
CVE-2019-3836 [HIGH] CVE-2019-3836: It was discovered in gnutls before version 3
It was discovered in gnutls before version 3.6.7 upstream that there is an uninitialized pointer access in gnutls versions 3.6.3 or later which can be triggered by certain post-handshake messages.
Ubuntu
GnuTLS vulnerabilities
vendor_ubuntu·2019-05-30·CVSS 5.9
CVE-2018-10844 [MEDIUM] GnuTLS vulnerabilities
Title: GnuTLS vulnerabilities
Summary: Several security issues were fixed in GnuTLS.
Eyal Ronen, Kenneth G. Paterson, and Adi Shamir discovered that GnuTLS was
vulnerable to a timing side-channel attack known as the "Lucky Thirteen"
issue. A remote attacker could possibly use this issue to perform
plaintext-recovery attacks via analysis of timing data. This issue only
affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2018-10844,
CVE-2018-10845, CVE-2018-10846)
Tavis Ormandy discovered that GnuTLS incorrectly handled memory when
verifying certain X.509 certificates. A remote attacker could use this
issue to cause GnuTLS to crash, resulting in a denial of service, or
possibly execute arbitrary code. This issue only affected Ubuntu 18.04 LTS,
Ubuntu 18.10, and Ubuntu 19.04. (CVE-2019-38
Red Hat
gnutls: invalid pointer access upon receiving async handshake messages
vendor_redhat·2019-03-27·CVSS 5.9
CVE-2019-3836 [MEDIUM] CWE-456 gnutls: invalid pointer access upon receiving async handshake messages
gnutls: invalid pointer access upon receiving async handshake messages
It was discovered in gnutls before version 3.6.7 upstream that there is an uninitialized pointer access in gnutls versions 3.6.3 or later which can be triggered by certain post-handshake messages.
A flaw was found in the way gnutls handled malformed TLS 1.3 asynchronous messages. An attacker could use this flaw to crash an application compiled with gnutls via invalid pointer access.
Package: gnutls (Red Hat Enterprise Linux 5) - Not affected
Package: gnutls (Red Hat Enterprise Linux 6) - Not affected
Package: gnutls (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2019-3836: gnutls28 - It was discovered in gnutls before version 3.6.7 upstream that there is an unini...
vendor_debian·2019·CVSS 5.9
CVE-2019-3836 [MEDIUM] CVE-2019-3836: gnutls28 - It was discovered in gnutls before version 3.6.7 upstream that there is an unini...
It was discovered in gnutls before version 3.6.7 upstream that there is an uninitialized pointer access in gnutls versions 3.6.3 or later which can be triggered by certain post-handshake messages.
Scope: local
bookworm: resolved (fixed in 3.6.7-2)
bullseye: resolved (fixed in 3.6.7-2)
forky: resolved (fixed in 3.6.7-2)
sid: resolved (fixed in 3.6.7-2)
trixie: resolved (fixed in 3.6.7-2)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-3836 gnutls: invalid pointer access upon receiving async handshake messages [fedora-all]
bugzilla·2019-03-27·CVSS 5.9
CVE-2019-3836 [MEDIUM] CVE-2019-3836 gnutls: invalid pointer access upon receiving async handshake messages [fedora-all]
CVE-2019-3836 gnutls: invalid pointer access upon receiving async handshake messages [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multipl
Bugzilla
CVE-2019-3836 gnutls: invalid pointer access upon receiving async handshake messages
bugzilla·2019-02-18·CVSS 5.9
CVE-2019-3836 [MEDIUM] CVE-2019-3836 gnutls: invalid pointer access upon receiving async handshake messages
CVE-2019-3836 gnutls: invalid pointer access upon receiving async handshake messages
It was discovered in gnutls upstream that there is an uninitialized pointer access in gnutls versions 3.6.4 or later which can be triggered by certain post-handshake messages.
Upstream issue:
https://gitlab.com/gnutls/gnutls/issues/704
Discussion:
Created gnutls tracking bugs for this issue:
Affects: fedora-all [bug 1693214]
---
the tlsfuzzer[1] test-tls13-keyupdate.py[2] test script can be used in concert with valgrind to verify the fix
1 - https://github.com/tomato42/tlsfuzzer
2 - https://github.com/tomato42/tlsfuzzer/pull/501
---
Hello!
according:
https://www.gnutls.org/security-new.html#GNUTLS-SA-2019-03-27
it seems that versions since 3.6.4 are affected (not 3.6.3 as originally pointed ou
CWE
Access of Uninitialized Pointer
mitre_cwe
CWE-824 Access of Uninitialized Pointer
CWE-824: Access of Uninitialized Pointer
The product accesses or uses a pointer that has not been initialized.
If the pointer contains an uninitialized value, then the value might not point to a valid memory location. This could cause the product to read from or write to unexpected memory locations, leading to a denial of service. If the uninitialized pointer is used as a function call, then arbitrary functions could be invoked. If an attacker can influence the portion of uninitialized memory that is contained in the pointer, this weakness could be leveraged to execute code or perform other attacks. Depending on memory layout, associated memory management behaviors, and product operation, the attacker might be able to influence the contents of the uninitialized pointer, thus gaining more
CWE
Missing Initialization of a Variable
mitre_cwe
CWE-456 Missing Initialization of a Variable
CWE-456: Missing Initialization of a Variable
The product does not initialize critical variables, which causes the execution environment to use unexpected values.
Modes of Introduction:
Phase: Implementation
Common Consequences:
Scope: Integrity, Other. Impact: Unexpected State, Quality Degradation, Varies by Context. The uninitialized data may be invalid, causing logic errors within the program. In some cases, this could result in a security problem.
Detection Methods:
Automated Static Analysis: Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without having to execute it. Typically, this is done by building a model of data flow and control flow, th
http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00017.htmlhttps://access.redhat.com/errata/RHSA-2019:3600https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3836https://gitlab.com/gnutls/gnutls/issues/704https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/A3ETBUFBB4G7AITAOUYPGXVMBGVXKUAN/https://security.gentoo.org/glsa/201904-14https://security.netapp.com/advisory/ntap-20190502-0005/https://usn.ubuntu.com/3999-1/http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00017.htmlhttps://access.redhat.com/errata/RHSA-2019:3600https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3836https://gitlab.com/gnutls/gnutls/issues/704https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/A3ETBUFBB4G7AITAOUYPGXVMBGVXKUAN/https://security.gentoo.org/glsa/201904-14https://security.netapp.com/advisory/ntap-20190502-0005/https://usn.ubuntu.com/3999-1/
2019-04-01
Published