Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-0567

Опубликовано: 16 янв. 2024
Источник: debian
EPSS Низкий

Описание

A vulnerability was found in GnuTLS, where a cockpit (which uses gnuTLS) rejects a certificate chain with distributed trust. This issue occurs when validating a certificate chain with cockpit-certificate-ensure. This flaw allows an unauthenticated, remote client or attacker to initiate a denial of service attack.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
gnutls28fixed3.8.3-1package
gnutls28fixed3.7.9-2+deb12u2bookwormpackage
gnutls28fixed3.7.1-5+deb11u5bullseyepackage
gnutls28not-affectedbusterpackage

Примечания

  • https://gitlab.com/gnutls/gnutls/-/issues/1521

  • https://gnutls.org/security-new.html#GNUTLS-SA-2024-01-09

  • https://lists.gnupg.org/pipermail/gnutls-help/2024-January/004841.html

  • https://gitlab.com/gnutls/gnutls/-/commit/9edbdaa84e38b1bfb53a7d72c1de44f8de373405 (3.8.3)

EPSS

Процентиль: 76%
0.01006
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 1 года назад

A vulnerability was found in GnuTLS, where a cockpit (which uses gnuTLS) rejects a certificate chain with distributed trust. This issue occurs when validating a certificate chain with cockpit-certificate-ensure. This flaw allows an unauthenticated, remote client or attacker to initiate a denial of service attack.

CVSS3: 7.5
redhat
больше 1 года назад

A vulnerability was found in GnuTLS, where a cockpit (which uses gnuTLS) rejects a certificate chain with distributed trust. This issue occurs when validating a certificate chain with cockpit-certificate-ensure. This flaw allows an unauthenticated, remote client or attacker to initiate a denial of service attack.

CVSS3: 7.5
nvd
больше 1 года назад

A vulnerability was found in GnuTLS, where a cockpit (which uses gnuTLS) rejects a certificate chain with distributed trust. This issue occurs when validating a certificate chain with cockpit-certificate-ensure. This flaw allows an unauthenticated, remote client or attacker to initiate a denial of service attack.

CVSS3: 7.5
msrc
больше 1 года назад

Описание отсутствует

CVSS3: 5.9
github
больше 1 года назад

A vulnerability was found in GnuTLS, where a cockpit (which uses gnuTLS) rejects a certificate chain with distributed trust. This issue occurs when validating a certificate chain with cockpit-certificate-ensure. This flaw allows an unauthenticated, remote client or attacker to initiate a denial of service attack.

EPSS

Процентиль: 76%
0.01006
Низкий