{"id":"CVE-2017-5334","details":"Double free vulnerability in the gnutls_x509_ext_import_proxy function in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allows remote attackers to have unspecified impact via crafted policy language information in an X.509 certificate with a Proxy Certificate Information extension.","modified":"2026-05-15T09:31:01.546365Z","published":"2017-03-24T15:59:00.763Z","database_specific":{"unresolved_ranges":[{"cpe":"cpe:2.3:o:opensuse:leap:42.1:*:*:*:*:*:*:*","extracted_events":[{"last_affected":"42.1"}],"source":"CPE_FIELD"},{"cpe":"cpe:2.3:o:opensuse:leap:42.2:*:*:*:*:*:*:*","extracted_events":[{"last_affected":"42.2"}],"source":"CPE_FIELD"}]},"references":[{"type":"ADVISORY","url":"http://lists.opensuse.org/opensuse-security-announce/2017-02/msg00005.html"},{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/95370"},{"type":"ADVISORY","url":"http://www.securitytracker.com/id/1037576"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2017:2292"},{"type":"ADVISORY","url":"https://gnutls.org/security.html#GNUTLS-SA-2017-1"},{"type":"FIX","url":"http://www.openwall.com/lists/oss-security/2017/01/10/7"},{"type":"FIX","url":"http://www.openwall.com/lists/oss-security/2017/01/11/4"},{"type":"FIX","url":"https://gitlab.com/gnutls/gnutls/commit/c5aaa488a3d6df712dc8dff23a049133cab5ec1b"},{"type":"FIX","url":"https://security.gentoo.org/glsa/201702-04"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/gnutls/gnutls","events":[{"introduced":"0"},{"last_affected":"58e5e8521b1f2298ee06596eb864268c50b6f344"},{"last_affected":"5e9cbaedbe157ba66801cf06b8730c69acb5a815"},{"last_affected":"2ce2a920aa3330b209c84c4be89819fc84ca3266"},{"last_affected":"bbabf49db6641e0f5ac8253e3e4eaf9fd35f7d89"},{"last_affected":"ca942f74569f01570bb8a54b336f2b7ed75a3477"},{"last_affected":"64fd6aa9e7c38b645c710aac036d4c5bd08b0b0c"},{"last_affected":"8b058a4d0d486d2d18cfda3ff52d9b9db3d11c3d"},{"last_affected":"759a586e553c9569a67ab1d5edc2931a7940e6c4"},{"last_affected":"8bfacc54e37b019ddd077f1f819b1bc8a51e59ad"}],"database_specific":{"cpe":["cpe:2.3:a:gnu:gnutls:*:*:*:*:*:*:*:*","cpe:2.3:a:gnu:gnutls:3.5.0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:gnutls:3.5.1:*:*:*:*:*:*:*","cpe:2.3:a:gnu:gnutls:3.5.2:*:*:*:*:*:*:*","cpe:2.3:a:gnu:gnutls:3.5.3:*:*:*:*:*:*:*","cpe:2.3:a:gnu:gnutls:3.5.4:*:*:*:*:*:*:*","cpe:2.3:a:gnu:gnutls:3.5.5:*:*:*:*:*:*:*","cpe:2.3:a:gnu:gnutls:3.5.6:*:*:*:*:*:*:*","cpe:2.3:a:gnu:gnutls:3.5.7:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"0"},{"last_affected":"3.3.25"},{"last_affected":"3.5.0"},{"last_affected":"3.5.1"},{"last_affected":"3.5.2"},{"last_affected":"3.5.3"},{"last_affected":"3.5.4"},{"last_affected":"3.5.5"},{"last_affected":"3.5.6"},{"last_affected":"3.5.7"}],"source":"CPE_FIELD"}}],"versions":["gnutls_3_5_7","gnutls_3_5_6","gnutls_3_3_25","gnutls_3_5_5","gnutls_3_5_4","gnutls_3_5_3","gnutls_3_3_24","gnutls_3_5_2","gnutls_3_5_1","gnutls_3_3_23","gnutls_3_5_0","gnutls_3_3_22","gnutls_3_3_21","gnutls_3_3_20","gnutls_3_3_19","gnutls_3_3_18","gnutls_3_3_17","gnutls_3_3_16","gnutls_3_4_3","gnutls_3_4_2","gnutls_3_3_15","gnutls_3_4_1","gnutls_3_4_0","gnutls_3_3_14","gnutls_3_3_13","gnutls_3_3_12","gnutls_3_3_11","gnutls_3_3_10","gnutls_3_3_9","gnutls_3_3_8","gnutls_3_3_7","gnutls_3_3_6","gnutls_3_3_5","gnutls_3_3_4","gnutls_3_3_3","gnutls_3_3_2","gnutls_3_3_1","gnutls_3_3_0","gnutls_3_2_6","gnutls_3_2_5","gnutls_3_2_4","gnutls_3_2_3","gnutls_3_2_3pre0","gnutls_3_2_2","gnutls_3_2_0","gnutls_3_1_9","gnutls_3_1_8","gnutls_3_1_7","gnutls_3_1_6","gnutls_3_1_5","gnutls_3_1_4","gnutls_3_1_3","gnutls_3_1_2","gnutls_3_1_0","gnutls_3_1_0pre0","gnutls_3_0_21","gnutls_3_0_18","gnutls_3_0_17","gnutls_3_0_16","gnutls_3_0_15","gnutls_3_0_14","gnutls_3_0_13","gnutls-3_0_12","gnutls_3_0_11","gnutls_3_0_10","gnutls_3_0_9","gnutls_3_0_8","gnutls_3_0_7","gnutls_3_0_6","gnutls_3_0_5","gnutls_3_0_4","gnutls_3_0_3","gnutls_3_0_2","gnutls_3_0_0","gnutls_2_99_4","gnutls_2_99_3","gnutls_2_99_2","gnutls_2_99_1","gnutls_2_99_0","gnutls_2_11_6","gnutls_2_11_5","gnutls_2_11_4","gnutls_2_11_3","gnutls_2_9_10","gnutls_2_9_9","gnutls_2_9_8","gnutls_2_9_7","gnutls_2_9_6","gnutls_2_9_5","gnutls_2_9_4","gnutls_2_9_3","gnutls_2_9_2","gnutls_2_7_12","gnutls_2_7_11","gnutls_2_7_10","gnutls_2_7_9","gnutls_2_7_8","gnutls_2_7_7","gnutls_2_7_6","gnutls_2_7_5","gnutls_2_7_4","gnutls_2_7_3","gnutls_2_7_1","gnutls_2_7_0","gnutls_2_5_8","gnutls_2_5_7","gnutls_2_5_6","gnutls_2_5_4","gnutls_2_5_3","gnutls_2_5_2","gnutls_2_5_1","gnutls_2_5_0","gnutls_2_4_0","gnutls_2_3_15","gnutls_2_3_14","gnutls_2_3_13","gnutls_2_3_12","gnutls_2_3_11","gnutls_2_3_10","gnutls_2_3_9","gnutls_2_3_8","gnutls_2_3_7","gnutls_2_3_6","gnutls_2_3_5","gnutls_2_3_3","gnutls_2_3_1","gnutls_2_3_0","gnutls_2_1_8","gnutls_2_1_7","gnutls_2_1_6","gnutls_2_1_5","gnutls_2_1_4","gnutls_2_1_3","gnutls_2_1_2","gnutls_2_0_1","gnutls_2_1_1","gnutls_2_1_0","gnutls_2_0_0","gnutls_1_7_19","gnutls_1_7_18","gnutls_1_7_17","gnutls_1_7_16","gnutls_1_7_15","gnutls_1_7_14","gnutls_1_7_13","gnutls_1_7_12","gnutls_1_7_11","gnutls_1_7_10","gnutls_1_7_9","gnutls_1_7_8","gnutls_1_7_7","gnutls_1_7_6","gnutls_1_7_5","gnutls_1_7_4","gnutls_1_7_3","gnutls_1_7_2","gnutls_1_7_1","gnutls_1_6_1","gnutls_1_7_0","gnutls_1_6_0","gnutls_1_5_5","gnutls_1_5_4","gnutls_1_5_3","gnutls_1_5_2","gnutls_1_5_1","gnutls_1_5_0","gnutls_1_4_2","gnutls_1_4_1","gnutls_1_4_0","gnutls_1_2_11","gnutls_1_3_5","gnutls_1_3_4","gnutls_1_2_10","gnutls_1_3_3","gnutls_1_3_2","gnutls_1_3_1","gnutls_1_3_0","gnutls_1_2_9","gnutls_1_2_8","gnutls_1_2_7","gnutls_1_2_6","gnutls_1_2_5","gnutls_1_2_4","gnutls_1_2_3","gnutls_1_0_25","gnutls_1_2_2","gnutls_1_2_1","gnutls_1_2_0","gnutls_1_0_24","gnutls_1_1_23","gnutls_1_0_23","gnutls_1_1_22","gnutls_1_0_22","gnutls_1_1_21","gnutls_1_1_20","gnutls_1_1_19","gnutls_1_0_21","gnutls_1_1_18","gnutls_1_1_17","gnutls_1_0_20","gnutls_1_1_16","gnutls_1_1_15","gnutls_1_1_14","gnutls_1_1_13","gnutls_1_1_12","gnutls_1_1_11","gnutls_1_1_10","gnutls_1_1_9","gnutls_1_1_8","gnutls_1_1_7","gnutls_1_1_7_pre0","gnutls_1_1_6","gnutls_1_1_5","gnutls_1_1_4","gnutls_1_1_3","gnutls_1_1_2","gnutls_1_1_1","gnutls_1_1_0","gnutls_1_0_0","gnutls_0_9_99","gnutls_0_9_98","gnutls_0_9_97","gnutls_0_9_96","gnutls_0_9_95","gnutls_0_9_94","gnutls_0_9_93","gnutls_0_9_92","gnutls_0_9_91","gnutls_0_9_90","gnutls_0_9_8","gnutls_0_9_7","gnutls_0_9_6","gnutls_0_9_5","gnutls_0_9_4","gnutls_0_9_3","gnutls_0_9_2","gnutls_0_9_1","gnutls_0_8_1","gnutls_0_8_0","gnutls_0_6_0","gnutls_0_5_11","gnutls_0_5_10","gnutls_0_5_x_before_int_fixes","gnutls_0_5_9","gnutls_0_5_8","gnutls_0_5_7","gnutls_0_5_6","gnutls_0_5_5","gnutls_0_5_x_before_types_change","gnutls_0_5_4","gnutls_0_5_x_with_export_ciphersuites","gnutls_0_5_x_before_export_ciphersuites","gnutls_0_5_1","gnutls_0_5_0","gnutls_0_4_with_libtasn1","gnutls_0_4_3","gnutls_0_4_2","gnutls_0_4_1","gnutls_0_4_0","gnutls_0_3_92","gnutls_0_3_91","gnutls_0_3_90","gnutls_0_3_2","gnutls_0_3_1","gnutls_0_3_0","gnutls_0_2_91","gnutls_0_2_90","gnutls_0_2_11","gnutls_0_2_10","gnutls_0_2_9","gnutls_0_2_4","gnutls_0_2_3","gnutls_0_2_2","gnutls_0_2_1","gnutls_0_2_0","gnutls_0_1_9","gnutls_0_1_4","gnutls-0_1_2","gnutls-0-1-0-srp","gnutls-0-0-7","gnutls0-0-6","gnutls0-0-5","gnutls0-0-4"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2017-5334.json"}},{"ranges":[{"type":"GIT","repo":"https://gitlab.com/gnutls/gnutls","events":[{"introduced":"0"},{"fixed":"c5aaa488a3d6df712dc8dff23a049133cab5ec1b"}],"database_specific":{"source":"REFERENCES"}}],"versions":["gnutls_3_5_7","gnutls_3_5_5","gnutls_3_5_4","gnutls_3_5_3","gnutls_3_5_2","gnutls_3_5_1","gnutls_3_5_0","gnutls_3_4_3","gnutls_3_4_2","gnutls_3_4_1","gnutls_3_4_0","gnutls_3_3_6","gnutls_3_3_5","gnutls_3_3_4","gnutls_3_3_3","gnutls_3_3_2","gnutls_3_3_1","gnutls_3_3_0","gnutls_3_2_6","gnutls_3_2_5","gnutls_3_2_4","gnutls_3_2_3","gnutls_3_2_3pre0","gnutls_3_2_2","gnutls_3_2_0","gnutls_3_1_9","gnutls_3_1_8","gnutls_3_1_7","gnutls_3_1_6","gnutls_3_1_5","gnutls_3_1_4","gnutls_3_1_3","gnutls_3_1_2","gnutls_3_1_0","gnutls_3_1_0pre0","gnutls_3_0_21","gnutls_3_0_18","gnutls_3_0_17","gnutls_3_0_16","gnutls_3_0_15","gnutls_3_0_14","gnutls_3_0_13","gnutls-3_0_12","gnutls_3_0_11","gnutls_3_0_10","gnutls_3_0_9","gnutls_3_0_8","gnutls_3_0_7","gnutls_3_0_6","gnutls_3_0_5","gnutls_3_0_4","gnutls_3_0_3","gnutls_3_0_2","gnutls_3_0_0","gnutls_2_99_4","gnutls_2_99_3","gnutls_2_99_2","gnutls_2_99_1","gnutls_2_99_0","gnutls_2_11_6","gnutls_2_11_5","gnutls_2_11_4","gnutls_2_11_3","gnutls_2_9_10","gnutls_2_9_9","gnutls_2_9_8","gnutls_2_9_7","gnutls_2_9_6","gnutls_2_9_5","gnutls_2_9_4","gnutls_2_9_3","gnutls_2_9_2","gnutls_2_7_12","gnutls_2_7_11","gnutls_2_7_10","gnutls_2_7_9","gnutls_2_7_8","gnutls_2_7_7","gnutls_2_7_6","gnutls_2_7_5","gnutls_2_7_4","gnutls_2_7_3","gnutls_2_7_1","gnutls_2_7_0","gnutls_2_5_8","gnutls_2_5_7","gnutls_2_5_6","gnutls_2_5_4","gnutls_2_5_3","gnutls_2_5_2","gnutls_2_5_1","gnutls_2_5_0","gnutls_2_4_0","gnutls_2_3_15","gnutls_2_3_14","gnutls_2_3_13","gnutls_2_3_12","gnutls_2_3_11","gnutls_2_3_10","gnutls_2_3_9","gnutls_2_3_8","gnutls_2_3_7","gnutls_2_3_6","gnutls_2_3_5","gnutls_2_3_3","gnutls_2_3_1","gnutls_2_3_0","gnutls_2_1_8","gnutls_2_1_7","gnutls_2_1_6","gnutls_2_1_5","gnutls_2_1_4","gnutls_2_1_3","gnutls_2_1_2","gnutls_2_0_1","gnutls_2_1_1","gnutls_2_1_0","gnutls_2_0_0","gnutls_1_7_19","gnutls_1_7_18","gnutls_1_7_17","gnutls_1_7_16","gnutls_1_7_15","gnutls_1_7_14","gnutls_1_7_13","gnutls_1_7_12","gnutls_1_7_11","gnutls_1_7_10","gnutls_1_7_9","gnutls_1_7_8","gnutls_1_7_7","gnutls_1_7_6","gnutls_1_7_5","gnutls_1_7_4","gnutls_1_7_3","gnutls_1_7_2","gnutls_1_7_1","gnutls_1_6_1","gnutls_1_7_0","gnutls_1_6_0","gnutls_1_5_5","gnutls_1_5_4","gnutls_1_5_3","gnutls_1_5_2","gnutls_1_5_1","gnutls_1_5_0","gnutls_1_4_2","gnutls_1_4_1","gnutls_1_4_0","gnutls_1_2_11","gnutls_1_3_5","gnutls_1_3_4","gnutls_1_2_10","gnutls_1_3_3","gnutls_1_3_2","gnutls_1_3_1","gnutls_1_3_0","gnutls_1_2_9","gnutls_1_2_8","gnutls_1_2_7","gnutls_1_2_6","gnutls_1_2_5","gnutls_1_2_4","gnutls_1_2_3","gnutls_1_0_25","gnutls_1_2_2","gnutls_1_2_1","gnutls_1_2_0","gnutls_1_0_24","gnutls_1_1_23","gnutls_1_0_23","gnutls_1_1_22","gnutls_1_0_22","gnutls_1_1_21","gnutls_1_1_20","gnutls_1_1_19","gnutls_1_0_21","gnutls_1_1_18","gnutls_1_1_17","gnutls_1_0_20","gnutls_1_1_16","gnutls_1_1_15","gnutls_1_1_14","gnutls_1_1_13","gnutls_1_1_12","gnutls_1_1_11","gnutls_1_1_10","gnutls_1_1_9","gnutls_1_1_8","gnutls_1_1_7","gnutls_1_1_7_pre0","gnutls_1_1_6","gnutls_1_1_5","gnutls_1_1_4","gnutls_1_1_3","gnutls_1_1_2","gnutls_1_1_1","gnutls_1_1_0","gnutls_1_0_0","gnutls_0_9_99","gnutls_0_9_98","gnutls_0_9_97","gnutls_0_9_96","gnutls_0_9_95","gnutls_0_9_94","gnutls_0_9_93","gnutls_0_9_92","gnutls_0_9_91","gnutls_0_9_90","gnutls_0_9_8","gnutls_0_9_7","gnutls_0_9_6","gnutls_0_9_5","gnutls_0_9_4","gnutls_0_9_3","gnutls_0_9_2","gnutls_0_9_1","gnutls_0_8_1","gnutls_0_8_0","gnutls_0_6_0","gnutls_0_5_11","gnutls_0_5_10","gnutls_0_5_x_before_int_fixes","gnutls_0_5_9","gnutls_0_5_8","gnutls_0_5_7","gnutls_0_5_6","gnutls_0_5_5","gnutls_0_5_x_before_types_change","gnutls_0_5_4","gnutls_0_5_x_with_export_ciphersuites","gnutls_0_5_x_before_export_ciphersuites","gnutls_0_5_1","gnutls_0_5_0","gnutls_0_4_with_libtasn1","gnutls_0_4_3","gnutls_0_4_2","gnutls_0_4_1","gnutls_0_4_0","gnutls_0_3_92","gnutls_0_3_91","gnutls_0_3_90","gnutls_0_3_2","gnutls_0_3_1","gnutls_0_3_0","gnutls_0_2_91","gnutls_0_2_90","gnutls_0_2_11","gnutls_0_2_10","gnutls_0_2_9","gnutls_0_2_4","gnutls_0_2_3","gnutls_0_2_2","gnutls_0_2_1","gnutls_0_2_0","gnutls_0_1_9","gnutls_0_1_4","gnutls-0_1_2","gnutls-0-1-0-srp","gnutls-0-0-7","gnutls0-0-6","gnutls0-0-5","gnutls0-0-4"],"database_specific":{"vanir_signatures":[{"deprecated":false,"signature_type":"Function","signature_version":"v1","id":"CVE-2017-5334-67ca8643","target":{"function":"gnutls_x509_ext_import_proxy","file":"lib/x509/x509_ext.c"},"digest":{"length":1353,"function_hash":"82094556275891819096425079825963826025"},"source":"https://gitlab.com/gnutls/gnutls@c5aaa488a3d6df712dc8dff23a049133cab5ec1b"},{"deprecated":false,"signature_type":"Line","signature_version":"v1","id":"CVE-2017-5334-b4e21cfa","target":{"file":"lib/x509/x509_ext.c"},"digest":{"threshold":0.9,"line_hashes":["150917150299527204238550918565018673212","258137038353953095289650914738464478871","135339264935733593513510551145870872009","116233858464629904553341753062658197968","235591580831071185561859608675424030654","128686666984476309351620182179354977741","261513582690003421010918448489934451011","85424201175373088872193120963088409077","247749818456834175102156970457987517805","205012209890996119791933647751480122642","12494744905278419130748711294675266126","131800784427751840082166244390997484836","231924797949209366637734880615401453130","204260388045718260731197895344328082773","11199174117081254621089284713986767055","101650205716146340066203021374540769963","223387064996358877541992415989946471508","303418657142305247625334193655344330285","237738088919463399067686111037568401410","318340440074960802180559316130205404003","286477188956461247585858813895877752773","73897673526827947204025732771220857530","121642567399900984688742641221306463573","286748104602403262642232279472973226892","71971598817892808662569054640879377145","76146210283600477817673749965383655289","261137047095142720427126482291731827025","314856752657025014462167886018252503993","25610571084553975619505899720960880030","34304825970000896862408577931686393736","237363968530839791661253016893846089003"]},"source":"https://gitlab.com/gnutls/gnutls@c5aaa488a3d6df712dc8dff23a049133cab5ec1b"}],"vanir_signatures_modified":"2026-05-15T09:31:01Z","source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2017-5334.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}