GnuTLS Vulnerability: Application Crash via Specially Crafted .pem Bundle
CVE-2024-28835
5MEDIUM
Key Information:
- Vendor
Red Hat
- Status
- Vendor
- CVE Published:
- 21 March 2024
What is CVE-2024-28835?
A flaw has been discovered in GnuTLS where an application crash can be induced when attempting to verify a specially crafted .pem bundle using the "certtool --verify-chain" command.
Affected Version(s)
Red Hat Enterprise Linux 9 0:3.7.6-23.el9_3.4
Red Hat Enterprise Linux 9 0:3.8.3-4.el9_4
Red Hat Enterprise Linux 9 0:3.7.6-23.el9_3.4