CVE-2024-0567: Gnutls: rejects certificate chain with distributed trust
A vulnerability was found in GnuTLS, where a cockpit (which uses gnuTLS) rejects a certificate chain with distributed trust. This issue occurs when validating a certificate chain with cockpit-certificate-ensure. This flaw allows an unauthenticated, remote client or attacker to initiate a denial of service attack.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2024-0567?
CVE-2024-0567 is classified as a medium severity vulnerability.
How do I fix CVE-2024-0567?
To fix CVE-2024-0567, update GnuTLS to version 3.8.3 or later for Red Hat or the appropriate patched version for your system.
What systems are affected by CVE-2024-0567?
CVE-2024-0567 affects versions of GnuTLS prior to 3.8.3, as well as specific Ubuntu and Debian package versions.
What can an attacker do with CVE-2024-0567?
An attacker can exploit CVE-2024-0567 to disrupt certificate chain validation, potentially allowing unauthorized access.
Is CVE-2024-0567 related to any specific products?
Yes, CVE-2024-0567 impacts products utilizing GnuTLS, such as IBM QRadar Network Packet Capture and various Linux distributions.