CVE-2017-5334 is a critical double free vulnerability in the gnutls_x509_ext_import_proxy function of GnuTLS versions before 3.3.26 and 3.5.8, affecting products like GNU GnuTLS and OpenSUSE. This flaw allows remote attackers to achieve high impact on confidentiality, integrity, and availability through crafted X.509 certificates containing Proxy Certificate Information extensions, earning a CVSS score of 9.8. While no public exploits (Metasploit, Nuclei, ExploitDB) are currently available and it's not listed in CISA's KEV catalog, its high FAUCET Risk Score and notable community discussion and media coverage suggest potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
42.1CPE matchmatch criteria | cpe:2.3:o:opensuse:leap:42.1:*:*:*:*:*:*:* | ||
42.2CPE matchmatch criteria | cpe:2.3:o:opensuse:leap:42.2:*:*:*:*:*:*:* | ||
<= 3.3.25CPE matchmatch criteria | cpe:2.3:a:gnu:gnutls:*:*:*:*:*:*:*:* | ||
3.5.0CPE matchmatch criteria | cpe:2.3:a:gnu:gnutls:3.5.0:*:*:*:*:*:*:* | ||
3.5.1CPE matchmatch criteria | cpe:2.3:a:gnu:gnutls:3.5.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.