Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-12243

Опубликовано: 10 фев. 2025
Источник: debian
EPSS Низкий

Описание

A flaw was found in GnuTLS, which relies on libtasn1 for ASN.1 data processing. Due to an inefficient algorithm in libtasn1, decoding certain DER-encoded certificate data can take excessive time, leading to increased resource consumption. This flaw allows a remote attacker to send a specially crafted certificate, causing GnuTLS to become unresponsive or slow, resulting in a denial-of-service condition.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
gnutls28fixed3.8.9-1experimentalpackage
gnutls28fixed3.8.9-2package

Примечания

  • https://www.gnutls.org/security-new.html#GNUTLS-SA-2025-02-07

  • https://lists.gnupg.org/pipermail/gnutls-help/2025-February/004875.html

  • https://gitlab.com/gnutls/gnutls/-/issues/1553

  • Fixed by: https://gitlab.com/gnutls/gnutls/-/commit/4760bc63531e3f5039e70ede91a20e1194410892 (3.8.9)

EPSS

Процентиль: 72%
0.00745
Низкий

Связанные уязвимости

CVSS3: 5.3
ubuntu
6 месяцев назад

A flaw was found in GnuTLS, which relies on libtasn1 for ASN.1 data processing. Due to an inefficient algorithm in libtasn1, decoding certain DER-encoded certificate data can take excessive time, leading to increased resource consumption. This flaw allows a remote attacker to send a specially crafted certificate, causing GnuTLS to become unresponsive or slow, resulting in a denial-of-service condition.

CVSS3: 5.3
redhat
6 месяцев назад

A flaw was found in GnuTLS, which relies on libtasn1 for ASN.1 data processing. Due to an inefficient algorithm in libtasn1, decoding certain DER-encoded certificate data can take excessive time, leading to increased resource consumption. This flaw allows a remote attacker to send a specially crafted certificate, causing GnuTLS to become unresponsive or slow, resulting in a denial-of-service condition.

CVSS3: 5.3
nvd
6 месяцев назад

A flaw was found in GnuTLS, which relies on libtasn1 for ASN.1 data processing. Due to an inefficient algorithm in libtasn1, decoding certain DER-encoded certificate data can take excessive time, leading to increased resource consumption. This flaw allows a remote attacker to send a specially crafted certificate, causing GnuTLS to become unresponsive or slow, resulting in a denial-of-service condition.

CVSS3: 5.3
msrc
5 месяцев назад

Описание отсутствует

suse-cvrf
5 месяцев назад

Security update for gnutls

EPSS

Процентиль: 72%
0.00745
Низкий