← All CVEs

CVE-2017-5334

critical · 9.8

Double free vulnerability in the gnutls_x509_ext_import_proxy function in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allows remote attackers to have unspecified impact via crafted policy language information in an X.509 certificate with a Proxy Certificate Information extension.

9.8
CVSS
32.8%
EPSS (exploit prob.)
98th
EPSS percentile
2017-03-24
Published

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-415

Affected products

VendorProductAffected versions
opensuseleap42.1
opensuseleap42.2
gnugnutls<= 3.3.25
gnugnutls3.5.0
gnugnutls3.5.1
gnugnutls3.5.2
gnugnutls3.5.3
gnugnutls3.5.4
gnugnutls3.5.5
gnugnutls3.5.6
gnugnutls3.5.7

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2017-5334