Double free vulnerability in the gnutlsx509extimportproxy function in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allows remote attackers to have unspecified impact via crafted policy language information in an X.509 certificate with a Proxy Certificate Information extension.
{
"versions": [
{
"introduced": "0"
},
{
"last_affected": "3.3.25"
},
{
"introduced": "0"
},
{
"last_affected": "3.5.0"
},
{
"introduced": "0"
},
{
"last_affected": "3.5.1"
},
{
"introduced": "0"
},
{
"last_affected": "3.5.2"
},
{
"introduced": "0"
},
{
"last_affected": "3.5.3"
},
{
"introduced": "0"
},
{
"last_affected": "3.5.4"
},
{
"introduced": "0"
},
{
"last_affected": "3.5.5"
},
{
"introduced": "0"
},
{
"last_affected": "3.5.6"
},
{
"introduced": "0"
},
{
"last_affected": "3.5.7"
}
]
}[
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "42.1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "42.2"
}
]
}
]
[
{
"signature_type": "Function",
"signature_version": "v1",
"target": {
"file": "lib/x509/x509_ext.c",
"function": "gnutls_x509_ext_import_proxy"
},
"id": "CVE-2017-5334-67ca8643",
"deprecated": false,
"source": "https://gitlab.com/gnutls/gnutls@c5aaa488a3d6df712dc8dff23a049133cab5ec1b",
"digest": {
"function_hash": "82094556275891819096425079825963826025",
"length": 1353.0
}
},
{
"signature_type": "Line",
"signature_version": "v1",
"target": {
"file": "lib/x509/x509_ext.c"
},
"id": "CVE-2017-5334-b4e21cfa",
"deprecated": false,
"source": "https://gitlab.com/gnutls/gnutls@c5aaa488a3d6df712dc8dff23a049133cab5ec1b",
"digest": {
"line_hashes": [
"150917150299527204238550918565018673212",
"258137038353953095289650914738464478871",
"135339264935733593513510551145870872009",
"116233858464629904553341753062658197968",
"235591580831071185561859608675424030654",
"128686666984476309351620182179354977741",
"261513582690003421010918448489934451011",
"85424201175373088872193120963088409077",
"247749818456834175102156970457987517805",
"205012209890996119791933647751480122642",
"12494744905278419130748711294675266126",
"131800784427751840082166244390997484836",
"231924797949209366637734880615401453130",
"204260388045718260731197895344328082773",
"11199174117081254621089284713986767055",
"101650205716146340066203021374540769963",
"223387064996358877541992415989946471508",
"303418657142305247625334193655344330285",
"237738088919463399067686111037568401410",
"318340440074960802180559316130205404003",
"286477188956461247585858813895877752773",
"73897673526827947204025732771220857530",
"121642567399900984688742641221306463573",
"286748104602403262642232279472973226892",
"71971598817892808662569054640879377145",
"76146210283600477817673749965383655289",
"261137047095142720427126482291731827025",
"314856752657025014462167886018252503993",
"25610571084553975619505899720960880030",
"34304825970000896862408577931686393736",
"237363968530839791661253016893846089003"
],
"threshold": 0.9
}
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-5334.json"