Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-0567


A vulnerability was found in GnuTLS, where a cockpit (which uses gnuTLS) rejects a certificate chain with distributed trust. This issue occurs when validating a certificate chain with cockpit-certificate-ensure. This flaw allows an unauthenticated, remote client or attacker to initiate a denial of service attack.


Published

2024-01-16T14:15:48.527

Last Modified

2024-11-21T08:46:53.563

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-347
  • Type: Primary
    CWE-347

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application gnu gnutls < 3.8.3 Yes
Operating System fedoraproject fedora 38 Yes
Operating System fedoraproject fedora 39 Yes
Application netapp active_iq_unified_manager - Yes
Operating System debian debian_linux 11.0 Yes

References