CVE-2024-28835
Published: 21 March 2024
A flaw has been discovered in GnuTLS where an application crash can be induced when attempting to verify a specially crafted .pem bundle using the "certtool --verify-chain" command.
Notes
Author | Note |
---|---|
mdeslaur | per Debian, introduced in 3.7.0 |
Priority
Status
Package | Release | Status |
---|---|---|
gnutls28 Launchpad, Ubuntu, Debian |
bionic |
Not vulnerable
(code not present)
|
focal |
Not vulnerable
(3.6.13-2ubuntu1.10)
|
|
jammy |
Released
(3.7.3-4ubuntu1.5)
|
|
mantic |
Released
(3.8.1-4ubuntu1.3)
|
|
noble |
Released
(3.8.3-1.1ubuntu3.1)
|
|
upstream |
Needs triage
|
|
xenial |
Not vulnerable
(code not present)
|
|
Patches: upstream: https://gitlab.com/gnutls/gnutls/-/commit/4a4cefef6c194f8fbbffd7fb19651219421b085b upstream: https://gitlab.com/gnutls/gnutls/-/commit/e369e67a62f44561d417cb233acc566cc696d82d |
References
- https://lists.gnupg.org/pipermail/gnutls-help/2024-March/004845.html
- https://www.gnutls.org/security-new.html#GNUTLS-SA-2024-01-23
- https://access.redhat.com/security/cve/CVE-2024-28835
- https://www.cve.org/CVERecord?id=CVE-2024-28835
- https://ubuntu.com/security/notices/USN-6733-1
- https://ubuntu.com/security/notices/USN-6733-2
- NVD
- Launchpad
- Debian