CVE-2019-3836
High
CVE-2019-3836
It was discovered in gnutls before version 3.6.7 upstream that there is an uninitialized pointer access in gnutls versions 3.6.3 or later which can be triggered by certain post-handshake messages.
Exploit probability
3.4%
Published
April 1, 2019
Required by
Not available
Last source change
August 7, 2026
02 / AFFECTED SOFTWARE
Affected packages
4 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Open Source Vulnerabilities
CVE-2019-3836
View original source
It was discovered in gnutls before version 3.6.7 upstream that there is an uninitialized pointer access in gnutls versions 3.6.3 or later which can be triggered by certain post-handshake messages.
05 / REFERENCES
Further evidence
- http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00017.html
- https://access.redhat.com/errata/RHSA-2019:3600
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3836
- https://gitlab.com/gnutls/gnutls/issues/704
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/A3ETBUFBB4G7AITAOUYPGXVMBGVXKUAN/
- https://security.gentoo.org/glsa/201904-14
- https://security.netapp.com/advisory/ntap-20190502-0005/
- https://usn.ubuntu.com/3999-1/