VDB

ALPINE-CVE-2019-3829

ALPINE-CVE-2019-3829 PUBLISHED CVSS 7.5 HIGH

A vulnerability was found in gnutls versions from 3.5.8 before 3.6.7. A memory corruption (double free) vulnerability in the certificate verification API. Any client or server application that verifies X.509 certificates with GnuTLS 3.5.8 or later is affected.

Risk Scores

CVSS 3.0
7.5
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected Products

VendorProductVersions
Alpine:v3.22gnutls0, 3.1.8-r1, 2.6.5-r0
Alpine:v3.10gnutls3.2.1-r1, 0, 3.1.7-r1
Alpine:v3.15gnutls3.5.8, 2.10.4-r0, 2.10.5-r0
Alpine:v3.14gnutls0, 3.5.8, 0
Alpine:v3.17gnutls3.6.1-r0, 0, 3.5.8
Alpine:v3.21gnutls0, 0, 2.10.4-r0
Alpine:v3.20gnutls3.5.8, 0, 2.10.4-r0
Alpine:v3.9gnutls3.1.4-r0, 0, 0
Alpine:v3.23gnutls3.5.8, 0, 2.10.4-r0
Alpine:v3.11gnutls3.5.8-r0, 0, 2.10.4-r0
Alpine:v3.13gnutls0, 2.10.4-r0, 3.5.8
Alpine:v3.18gnutls3.3.8-r0, 3.5.8, 0
Alpine:v3.24gnutls0, 3.5.8
Alpine:v3.16gnutls0, 3.4.2-r0, 3.6.2-r0
Alpine:v3.19gnutls3.0.22-r0, 0, 2.10.4-r0
Alpine:v3.12gnutls3.5.11-r0, 0, 2.10.4-r0
Alpine:v3.8gnutls0, 3.5.8, 0

Timeline

  • Mar 27, 2019 CVE Published
  • Apr 30, 2026 Distribution Patch
  • Jul 8, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›