cbcvebase.
CVE-2024-28835
published 2024-03-21

CVE-2024-28835: A flaw has been discovered in GnuTLS where an application crash can be induced when attempting to verify a specially crafted .pem bundle using the "certtool…

PriorityP417medium5CVSS 3.1
AVLACLPRLUIRSUCNINAH
EPSS
0.39%
30.9th percentile
A flaw has been discovered in GnuTLS where an application crash can be induced when attempting to verify a specially crafted .pem bundle using the "certtool --verify-chain" command.

Affected

6 ranges
VendorProductVersion rangeFixed in
debiangnutls28< gnutls28 3.7.9-2+deb12u3 (bookworm)gnutls28 3.7.9-2+deb12u3 (bookworm)
msrcazl3_gnutls_3.8.3-2_on_azure_linux_3.0
msrcazl3_gnutls_3.8.3-4_on_azure_linux_3.0
msrcazure_linux_3.0_arm
msrcazure_linux_3.0_x64
msrccbl2_gnutls_3.7.11-1_on_cbl_mariner_2.0

CVSS provenance

nvdv3.15.0MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H
osv5.3MEDIUM
vendor_ubuntu5.3MEDIUM
vendor_debian5.0MEDIUM
vendor_msrc5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.