Insecure digital certificates In gnutls28
Description
A vulnerability was found in GnuTLS, where a cockpit (which uses gnuTLS) rejects a certificate chain with distributed trust. This issue occurs when validating a certificate chain with cockpit-certificate-ensure. This flaw allows an unauthenticated, remote client or attacker to initiate a denial of service attack.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
debian 11 | 3.7.1-5+deb11u5 | ||
alpine v3.18 | 3.8.3-r0 | ||
alpine v3.19 | 3.8.3-r0 | ||
alpine v3.20 | 3.8.3-r0 | ||
alpine v3.21 | 3.8.3-r0 | ||
alpine v3.22 | 3.8.3-r0 | ||
debian 12 | 3.7.9-2+deb12u2 | ||
debian 13 | 3.8.3-1 | ||
debian 14 | 3.8.3-1 | ||
alpine v3.23 | 3.8.3-r0 |
1-10 of 16
10
Aliases
1. 2. 3. 4. 5. 6. 7.