Logo
vulnerabilityCVE-2024-12243
Name
CVE-2024-12243
Source
NVD ( link)Debian ( link)
Description
A flaw was found in GnuTLS, which relies on libtasn1 for ASN.1 data processing. Due to an inefficient algorithm in libtasn1, decoding certain DER-encoded certificate data can take excessive time, leading to increased resource consumption. This flaw allows a remote attacker to send a specially crafted certificate, causing GnuTLS to become unresponsive or slow, resulting in a denial-of-service condition.
Published Date
Updated Date
Workaround
-
Advisories

Analysis#


Affected Component
Analysis
gnutls
Patched

Vulnerability Ratings#


5.3
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
3.8.13
Not Affected
buildroot
master
3.8.13
Not Affected
openwrt
master
3.8.10-r1
Not Affected
openwrt
openwrt-25.12
3.8.10-r1
Not Affected
yocto
master
3.8.13
Not Affected
yocto
scarthgap
3.8.4
Patched

Resolved with patches#


gnutls (yocto:kirkstone)

#
Title
Author
Resolve
1
x509: optimize name constraints processing
Daiki Ueno <ueno@gnu.org>
CVE-2024-12243

gnutls (yocto:scarthgap)

#
Title
Author
Resolve
1
x509: optimize name constraints processing
Daiki Ueno <ueno@gnu.org>
CVE-2024-12243