CVE-2019-3836 PUBLISHED CVSS 5.900000095367432 MEDIUM

It was discovered in gnutls before version 3.6.7 upstream that there is an uninitialized pointer access in gnutls versions 3.6.3 or later which can be triggered by certain post-handshake messages.

EPSS 0.36% · 58.1th percentile

Risk Scores

CVSS v3.0
5.900000095367432
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
0.36%
58.1th percentile

Affected Products

VendorProductVersions
fedoraprojectfedora28
gnutlsgnutlsfixed in gnutls 3.6.7
opensuseleap15.0
gnugnutls3.6.3

Timeline

References

Open in Interactive Console →