It was discovered in gnutls before version 3.6.7 upstream that there is an uninitialized pointer access in gnutls versions 3.6.3 or later which can be triggered by certain post-handshake messages.
The product does not initialize critical variables, which causes the execution environment to use unexpected values.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Gnutls | Gnu | 3.6.3 (including) | 3.6.7 (excluding) |
Red Hat Enterprise Linux 8 | RedHat | gnutls-0:3.6.8-8.el8 | * |
Red Hat Enterprise Linux 8 | RedHat | gnutls-0:3.6.8-8.el8 | * |
Gnutls28 | Ubuntu | cosmic | * |
Gnutls28 | Ubuntu | disco | * |
Gnutls28 | Ubuntu | upstream | * |