Environment Variable Misconfiguration in Fetch Library by FreeBSD
CVE-2024-45289

7.5HIGH

Key Information:

Vendor

FreeBSD

Status
Vendor
CVE Published:
12 November 2024

What is CVE-2024-45289?

The Fetch library in FreeBSD has a flaw where it incorrectly utilizes environment variables to manage critical information like the revocation file pathname. Specifically, the environment variable name employed by fetch(1) to relay the filename to the library is faulty, resulting in the revocation option being disregarded. Consequently, this misconfiguration permits Fetch to establish connections with hosts that present certificates listed in the revocation file specified within the --crl option, potentially compromising certificate validation integrity.

Affected Version(s)

FreeBSD 14.1-RELEASE

FreeBSD 13.4-RELEASE

FreeBSD 13.3-RELEASE

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

Credit

Franco Fichtner
.