UBUNTU-CVE-2024-12243
Dashboard / Vulnerabilities / UBUNTU-CVE-2024-12243
UBUNTU-CVE-2024-12243
Summary:
Details: A flaw was found in GnuTLS, which relies on libtasn1 for ASN.1 data processing. Due to an inefficient algorithm in libtasn1, decoding certain DER-encoded certificate data can take excessive time, leading to increased resource consumption. This flaw allows a remote attacker to send a specially crafted certificate, causing GnuTLS to become unresponsive or slow, resulting in a denial-of-service condition.
References: https://ubuntu.com/security/CVE-2024-12243, https://www.cve.org/CVERecord?id=CVE-2024-12243, https://www.gnutls.org/security-new.html#GNUTLS-SA-2025-02-07, https://lists.gnupg.org/pipermail/gnutls-help/2025-February/004875.html, https://access.redhat.com/security/cve/CVE-2024-12243, https://ubuntu.com/security/notices/USN-7281-1, https://ubuntu.com/security/notices/USN-8502-1
Affected packages
Package
Name: gnutls28
Purl: pkg:deb/ubuntu/gnutls28?arch=source&distro=esm-infra%2Fbionic
Affected ranges
Type: ECOSYSTEM
Events:
