Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-28835

Опубликовано: 21 мар. 2024
Источник: redhat
CVSS3: 5

Описание

A flaw has been discovered in GnuTLS where an application crash can be induced when attempting to verify a specially crafted .pem bundle using the "certtool --verify-chain" command.

Отчет

The observed crash in GnuTLS during certificate chain verification, triggered by a specific certificate configuration, represents a moderate severity issue due to its potential impact on security-critical operations reliant on certificate validation. The crash may indicate an underlying flaw in GnuTLS's handling of certain certificate attributes or structures, potentially exposing systems to denial-of-service vulnerabilities or bypassing security checks if exploited maliciously. Given that certificate validation is a fundamental aspect of secure communication protocols such as TLS, the inability to reliably verify certificate chains could lead to unauthorized access, data integrity breaches, or interception of sensitive information.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10gnutlsAffected
Red Hat Enterprise Linux 6gnutlsOut of support scope
Red Hat Enterprise Linux 7gnutlsOut of support scope
Red Hat Enterprise Linux 8gnutlsNot affected
Red Hat Enterprise Linux 9gnutlsFixedRHSA-2024:187918.04.2024
Red Hat Enterprise Linux 9gnutlsFixedRHSA-2024:257030.04.2024
Red Hat Enterprise Linux 9gnutlsFixedRHSA-2024:187918.04.2024
Red Hat Enterprise Linux 9gnutlsFixedRHSA-2024:257030.04.2024
Red Hat Enterprise Linux 9.2 Extended Update SupportgnutlsFixedRHSA-2024:288916.05.2024

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-248
https://bugzilla.redhat.com/show_bug.cgi?id=2269084gnutls: potential crash during chain building/verification

5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5
ubuntu
больше 1 года назад

A flaw has been discovered in GnuTLS where an application crash can be induced when attempting to verify a specially crafted .pem bundle using the "certtool --verify-chain" command.

CVSS3: 5
nvd
больше 1 года назад

A flaw has been discovered in GnuTLS where an application crash can be induced when attempting to verify a specially crafted .pem bundle using the "certtool --verify-chain" command.

CVSS3: 5
msrc
8 месяцев назад

Описание отсутствует

CVSS3: 5
debian
больше 1 года назад

A flaw has been discovered in GnuTLS where an application crash can be ...

CVSS3: 5
github
больше 1 года назад

A flaw has been discovered in GnuTLS where an application crash can be induced when attempting to verify a specially crafted .pem bundle using the "certtool --verify-chain" command.

5 Medium

CVSS3