A flaw has been discovered in GnuTLS where an application crash can be induced when attempting to verify a specially crafted .pem bundle using the certtool –verify-chain command.
An exception is thrown from a function, but it is not caught.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Red Hat Enterprise Linux 9 | RedHat | gnutls-0:3.7.6-23.el9_3.4 | * |
Red Hat Enterprise Linux 9 | RedHat | gnutls-0:3.8.3-4.el9_4 | * |
Red Hat Enterprise Linux 9 | RedHat | gnutls-0:3.7.6-23.el9_3.4 | * |
Red Hat Enterprise Linux 9 | RedHat | gnutls-0:3.8.3-4.el9_4 | * |
Red Hat Enterprise Linux 9.2 Extended Update Support | RedHat | gnutls-0:3.7.6-21.el9_2.3 | * |
Gnutls28 | Ubuntu | devel | * |
Gnutls28 | Ubuntu | jammy | * |
Gnutls28 | Ubuntu | mantic | * |
Gnutls28 | Ubuntu | noble | * |