7.5 High
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
0.002 Low
EPSS
Percentile
55.8%
A double free error occurs during verification of pkcs7 signatures in gnutls_pkcs7_verify function. (CVE-2022-2509)
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
Mageia | 8 | noarch | gnutls | < 3.6.15-3.3 | gnutls-3.6.15-3.3.mga8 |
bugs.mageia.org/show_bug.cgi?id=30691
lists.fedoraproject.org/archives/list/[email protected]/thread/5NRKG3OBVPVFJTDYYF6SZH5KZIWFLVPW/
lists.suse.com/pipermail/sle-security-updates/2022-August/011930.html
ubuntu.com/security/notices/USN-5550-1
www.debian.org/security/2022/dsa-5203
www.gnutls.org/security-new.html#GNUTLS-SA-2022-07-07