CVE Vulnerabilities

CVE-2017-5334

Double Free

Published: Mar 24, 2017 | Modified: Oct 30, 2018
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
5.3 MODERATE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Ubuntu
MEDIUM

Double free vulnerability in the gnutls_x509_ext_import_proxy function in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allows remote attackers to have unspecified impact via crafted policy language information in an X.509 certificate with a Proxy Certificate Information extension.

Weakness

The product calls free() twice on the same memory address, potentially leading to modification of unexpected memory locations.

Affected Software

Name Vendor Start Version End Version
Leap Opensuse 42.1 (including) 42.1 (including)
Leap Opensuse 42.2 (including) 42.2 (including)
Gnutls28 Ubuntu artful *
Gnutls28 Ubuntu bionic *
Gnutls28 Ubuntu cosmic *
Gnutls28 Ubuntu devel *
Gnutls28 Ubuntu disco *
Gnutls28 Ubuntu precise *
Gnutls28 Ubuntu trusty *
Gnutls28 Ubuntu upstream *
Gnutls28 Ubuntu vivid/stable-phone-overlay *
Gnutls28 Ubuntu vivid/ubuntu-core *
Gnutls28 Ubuntu xenial *
Gnutls28 Ubuntu yakkety *
Gnutls28 Ubuntu zesty *
Red Hat Enterprise Linux 7 RedHat gnutls-0:3.3.26-9.el7 *

Potential Mitigations

References