Environment Variable Misconfiguration in Fetch Library by FreeBSD
CVE-2024-45289
7.5HIGH
What is CVE-2024-45289?
The Fetch library in FreeBSD has a flaw where it incorrectly utilizes environment variables to manage critical information like the revocation file pathname. Specifically, the environment variable name employed by fetch(1) to relay the filename to the library is faulty, resulting in the revocation option being disregarded. Consequently, this misconfiguration permits Fetch to establish connections with hosts that present certificates listed in the revocation file specified within the --crl option, potentially compromising certificate validation integrity.
Affected Version(s)
FreeBSD 14.1-RELEASE
FreeBSD 13.4-RELEASE
FreeBSD 13.3-RELEASE