NA

CVE-2024-0567

Published: 16/01/2024 Updated: 05/03/2024
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

A vulnerability was found in GnuTLS, where a cockpit (which uses gnuTLS) rejects a certificate chain with distributed trust. This issue occurs when validating a certificate chain with cockpit-certificate-ensure. This flaw allows an unauthenticated, remote client or malicious user to initiate a denial of service attack.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

gnu gnutls

Vendor Advisories

Synopsis Moderate: gnutls security update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for gnutls is now available for Red Hat Enterprise Linux 9Red Hat Product Security has rated this update as having a secu ...
Debian Bug report logs - #1061045 gnutls28: CVE-2024-0567 Package: src:gnutls28; Maintainer for src:gnutls28 is Debian GnuTLS Maintainers <pkg-gnutls-maint@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Tue, 16 Jan 2024 21:15:01 UTC Severity: important Tags: security, upstream ...
Description<!---->A vulnerability was found in GnuTLS, where a cockpit (which uses gnuTLS) rejects a certificate chain with distributed trust This issue occurs when validating a certificate chain with cockpit-certificate-ensure This flaw allows an unauthenticated, remote client or attacker to initiate a denial of service attackA vulnerability wa ...