Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-28835

Опубликовано: 21 мар. 2024
Источник: debian

Описание

A flaw has been discovered in GnuTLS where an application crash can be induced when attempting to verify a specially crafted .pem bundle using the "certtool --verify-chain" command.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
gnutls28fixed3.8.4-1experimentalpackage
gnutls28fixed3.8.4-2package
gnutls28fixed3.7.9-2+deb12u3bookwormpackage
gnutls28not-affectedbusterpackage

Примечания

  • https://bugzilla.redhat.com/show_bug.cgi?id=2269084

  • https://gitlab.com/gnutls/gnutls/-/issues/1525

  • https://gitlab.com/gnutls/gnutls/-/issues/1527

  • https://lists.gnupg.org/pipermail/gnutls-help/2024-March/004845.html

  • https://www.gnutls.org/security-new.html#GNUTLS-SA-2024-01-23

  • Fixed by: https://gitlab.com/gnutls/gnutls/-/commit/e369e67a62f44561d417cb233acc566cc696d82d (3.8.4)

  • Introduced with: https://gitlab.com/gnutls/gnutls/-/commit/d268f19510a95f92d11d8f8dc7d94fcae4d765cc (3.7.0)

Связанные уязвимости

CVSS3: 5
ubuntu
больше 1 года назад

A flaw has been discovered in GnuTLS where an application crash can be induced when attempting to verify a specially crafted .pem bundle using the "certtool --verify-chain" command.

CVSS3: 5
redhat
больше 1 года назад

A flaw has been discovered in GnuTLS where an application crash can be induced when attempting to verify a specially crafted .pem bundle using the "certtool --verify-chain" command.

CVSS3: 5
nvd
больше 1 года назад

A flaw has been discovered in GnuTLS where an application crash can be induced when attempting to verify a specially crafted .pem bundle using the "certtool --verify-chain" command.

CVSS3: 5
msrc
8 месяцев назад

Описание отсутствует

CVSS3: 5
github
больше 1 года назад

A flaw has been discovered in GnuTLS where an application crash can be induced when attempting to verify a specially crafted .pem bundle using the "certtool --verify-chain" command.