Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2024-6119

Опубликовано: 03 сент. 2024
Источник: ubuntu
Приоритет: medium
EPSS Средний
CVSS3: 7.5

Описание

Issue summary: Applications performing certificate name checks (e.g., TLS clients checking server certificates) may attempt to read an invalid memory address resulting in abnormal termination of the application process. Impact summary: Abnormal termination of an application can a cause a denial of service. Applications performing certificate name checks (e.g., TLS clients checking server certificates) may attempt to read an invalid memory address when comparing the expected name with an otherName subject alternative name of an X.509 certificate. This may result in an exception that terminates the application program. Note that basic certificate chain validation (signatures, dates, ...) is not affected, the denial of service can occur only when the application also specifies an expected DNS name, Email address or IP address. TLS servers rarely solicit client certificates, and even when they do, they generally don't perform a name check against a reference identifier (expected ident...

РелизСтатусПримечание
devel

not-affected

2025.02-8ubuntu1
esm-apps-legacy/xenial

not-affected

openssl 3.x only
esm-apps/bionic

not-affected

openssl 3.x only
esm-apps/xenial

not-affected

openssl 3.x only
esm-infra/focal

not-affected

openssl 3.x only
focal

not-affected

openssl 3.x only
jammy

not-affected

openssl 3.x only
mantic

not-affected

openssl 3.x only
noble

released

2024.02-2ubuntu0.6
oracular

ignored

end of life, was needed

Показывать по

РелизСтатусПримечание
devel

not-affected

uses system openssl
esm-apps-legacy/xenial

needs-triage

esm-apps/bionic

needs-triage

esm-apps/focal

not-affected

uses system openssl
esm-apps/jammy

needs-triage

esm-apps/noble

not-affected

uses system openssl
esm-apps/resolute

not-affected

uses system openssl
esm-apps/xenial

ignored

end of ESM support, was needs-triage
esm-infra-legacy/trusty

not-affected

uses system openssl
focal

not-affected

uses system openssl

Показывать по

РелизСтатусПримечание
devel

released

3.3.1-2ubuntu2
esm-infra-legacy/trusty

not-affected

3.x only
esm-infra-legacy/xenial

not-affected

3.x only
esm-infra/bionic

not-affected

3.x only
esm-infra/focal

not-affected

3.x only
esm-infra/xenial

not-affected

3.x only
fips-preview/jammy

needed

fips-updates/bionic

not-affected

3.x only
fips-updates/focal

not-affected

3.x only
fips-updates/jammy

released

3.0.2-0ubuntu1.18+Fips1

Показывать по

РелизСтатусПримечание
devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra-legacy/xenial

DNE

esm-infra/bionic

DNE

esm-infra/focal

DNE

esm-infra/xenial

DNE

fips-preview/jammy

needs-triage

fips-updates/bionic

DNE

fips-updates/focal

DNE

fips-updates/jammy

needs-triage

Показывать по

РелизСтатусПримечание
devel

DNE

esm-infra/bionic

not-affected

3.x only
esm-infra/focal

DNE

focal

DNE

jammy

DNE

noble

DNE

oracular

DNE

plucky

DNE

questing

DNE

resolute

DNE

Показывать по

EPSS

Процентиль: 99%
0.66582
Средний

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 5.9
redhat
почти 2 года назад

Issue summary: Applications performing certificate name checks (e.g., TLS clients checking server certificates) may attempt to read an invalid memory address resulting in abnormal termination of the application process. Impact summary: Abnormal termination of an application can a cause a denial of service. Applications performing certificate name checks (e.g., TLS clients checking server certificates) may attempt to read an invalid memory address when comparing the expected name with an `otherName` subject alternative name of an X.509 certificate. This may result in an exception that terminates the application program. Note that basic certificate chain validation (signatures, dates, ...) is not affected, the denial of service can occur only when the application also specifies an expected DNS name, Email address or IP address. TLS servers rarely solicit client certificates, and even when they do, they generally don't perform a name check against a reference identifier (expected ident...

CVSS3: 7.5
nvd
почти 2 года назад

Issue summary: Applications performing certificate name checks (e.g., TLS clients checking server certificates) may attempt to read an invalid memory address resulting in abnormal termination of the application process. Impact summary: Abnormal termination of an application can a cause a denial of service. Applications performing certificate name checks (e.g., TLS clients checking server certificates) may attempt to read an invalid memory address when comparing the expected name with an `otherName` subject alternative name of an X.509 certificate. This may result in an exception that terminates the application program. Note that basic certificate chain validation (signatures, dates, ...) is not affected, the denial of service can occur only when the application also specifies an expected DNS name, Email address or IP address. TLS servers rarely solicit client certificates, and even when they do, they generally don't perform a name check against a reference identifier (expected iden

CVSS3: 7.5
msrc
почти 2 года назад

Possible denial of service in X.509 name checks

CVSS3: 7.5
debian
почти 2 года назад

Issue summary: Applications performing certificate name checks (e.g., ...

suse-cvrf
около 1 года назад

Security update for openssl-3

EPSS

Процентиль: 99%
0.66582
Средний

7.5 High

CVSS3

Уязвимость CVE-2024-6119