CVE-2015-3308: Double Free
Published Sep 2, 2015
·Updated
Double free vulnerability in lib/x509/x509ext.c in GnuTLS before 3.3.14 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted CRL distribution point.
Affected Software
2 affected components
GNU GnuTLS<=3.3.13
Canonical Ubuntu Linux=15.04
Event History
Sep 2, 2015
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-3308?
CVE-2015-3308 has a medium severity level due to the potential for denial of service and possible unspecified impacts.
2
How do I fix CVE-2015-3308?
To fix CVE-2015-3308, upgrade GnuTLS to version 3.3.14 or later.
3
Which versions of GnuTLS are affected by CVE-2015-3308?
CVE-2015-3308 affects all versions of GnuTLS prior to 3.3.14.
4
What can an attacker do with CVE-2015-3308?
An attacker can exploit CVE-2015-3308 to cause a denial of service by creating a crafted CRL distribution point.
5
Is CVE-2015-3308 present in Ubuntu 15.04?
Yes, CVE-2015-3308 is present in Ubuntu 15.04 as it includes an affected version of GnuTLS.