CVE-2019-3829: Double Free
A flaw was found in gnutls 3.5.8 or later. A use-after-free in multi-threaded-clients and a double-free vulnerability in single-threaded clients because gnutlsx509getsignature does not clear signature->data in the cleanup path.
Upstream bug: https://gitlab.com/gnutls/gnutls/issues/694
Other sources
A vulnerability was found in gnutls versions from 3.5.8 before 3.6.7. A memory corruption (double free) vulnerability in the certificate verification API. Any client or server application that verifies X.509 certificates with GnuTLS 3.5.8 or later is affected.
— Launchpad
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2019-3829?
CVE-2019-3829 is a memory corruption vulnerability in gnutls versions from 3.5.8 before 3.6.7.
Which software is affected by CVE-2019-3829?
Any client or server application that verifies X.509 certificates with GnuTLS 3.5.8 or later is affected.
What is the severity of CVE-2019-3829?
CVE-2019-3829 has a high severity with a CVSS score of 7.5.
How do I fix CVE-2019-3829?
To fix CVE-2019-3829, update to gnutls version 3.6.7 or later.
Where can I find more information about CVE-2019-3829?
You can find more information about CVE-2019-3829 at the following references: [1](http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00017.html), [2](https://access.redhat.com/errata/RHSA-2019:3600), [3](https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3829).