NA

CVE-2024-28835

Published: 21/03/2024 Updated: 01/05/2024

Vulnerability Summary

A flaw has been discovered in GnuTLS where an application crash can be induced when attempting to verify a specially crafted .pem bundle using the "certtool --verify-chain" command.

Vendor Advisories

Debian Bug report logs - #1067463 gnutls28: CVE-2024-28835 Package: src:gnutls28; Maintainer for src:gnutls28 is Debian GnuTLS Maintainers <pkg-gnutls-maint@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 21 Mar 2024 21:21:01 UTC Severity: important Tags: security, upstream ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> oss-sec mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> Re: GnuTLS 384 released, fixes CVE-2024-28834 &amp; CVE-2024-28835 <!--X-Subject-Header-End--> <!--X-Head-of-Message--> Fr ...
<!--X-Body-Begin--> <!--X-User-Header--> oss-sec mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> GnuTLS 384 released, fixes CVE-2024-28834 &amp; CVE-2024-28835 <!--X-Subject-Header-End--> <!--X-Head-of-Message--> From: ...