MGASA-2019-0134

Source
https://advisories.mageia.org/MGASA-2019-0134.html
Import Source
https://advisories.mageia.org/MGASA-2019-0134.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2019-0134
Related
Published
2019-04-05T18:12:59Z
Modified
2019-04-05T17:38:11Z
Summary
Updated gnutls packages fix security vulnerability
Details

A vulnerability was found in gnutls versions from 3.5.8 before 3.6.7. A memory corruption (double free) vulnerability in the certificate verification API. Any client or server application that verifies X.509 certificates with GnuTLS 3.5.8 or later is affected. (CVE-2019-3829)

References
Credits

Affected packages

Mageia:6 / gnutls

Package

Name
gnutls
Purl
pkg:rpm/mageia/gnutls?distro=mageia-6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.5.13-1.3.mga6

Ecosystem specific

{
    "section": "core"
}