First published: Wed Sep 02 2015(Updated: )
Double free vulnerability in lib/x509/x509_ext.c in GnuTLS before 3.3.14 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted CRL distribution point.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GnuTLS | <=3.3.13 | |
Ubuntu | =15.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-3308 has a medium severity level due to the potential for denial of service and possible unspecified impacts.
To fix CVE-2015-3308, upgrade GnuTLS to version 3.3.14 or later.
CVE-2015-3308 affects all versions of GnuTLS prior to 3.3.14.
An attacker can exploit CVE-2015-3308 to cause a denial of service by creating a crafted CRL distribution point.
Yes, CVE-2015-3308 is present in Ubuntu 15.04 as it includes an affected version of GnuTLS.