Search CVE reports


Toggle filters

31 – 40 of 357 results


CVE-2024-12243

Medium priority

Some fixes available 5 of 7

A flaw was found in GnuTLS, which relies on libtasn1 for ASN.1 data processing. Due to an inefficient algorithm in libtasn1, decoding certain DER-encoded certificate data can take excessive time, leading to increased resource...

1 affected package

gnutls28

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gnutls28 Fixed Fixed Fixed Needs evaluation
Show less packages

CVE-2024-0567

Medium priority
Fixed

A vulnerability was found in GnuTLS, where a cockpit (which uses gnuTLS) rejects a certificate chain with distributed trust. This issue occurs when validating a certificate chain with cockpit-certificate-ensure. This flaw allows...

1 affected package

gnutls28

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gnutls28 Fixed Fixed Not affected Not affected
Show less packages

CVE-2024-0553

Medium priority

Some fixes available 7 of 9

A vulnerability was found in GnuTLS. The response times to malformed ciphertexts in RSA-PSK ClientKeyExchange differ from the response times of ciphertexts with correct PKCS#1 v1.5 padding. This issue may allow a remote attacker...

1 affected package

gnutls28

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gnutls28 Fixed Fixed Fixed Needs evaluation
Show less packages

CVE-2023-5981

Medium priority

Some fixes available 5 of 6

A vulnerability was found that the response times to malformed ciphertexts in RSA-PSK ClientKeyExchange differ from response times of ciphertexts with correct PKCS#1 v1.5 padding.

1 affected package

gnutls28

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gnutls28 Fixed Fixed Fixed
Show less packages

CVE-2023-25824

Medium priority
Vulnerable

Mod_gnutls is a TLS module for Apache HTTPD based on GnuTLS. Versions from 0.9.0 to 0.12.0 (including) did not properly fail blocking read operations on TLS connections when the transport hit timeouts. Instead it entered...

1 affected package

mod-gnutls

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mod-gnutls Not in release Vulnerable Vulnerable Not affected
Show less packages

CVE-2023-25588

Medium priority
Fixed

A flaw was found in Binutils. The field `the_bfd` of `asymbol`struct is uninitialized in the `bfd_mach_o_get_synthetic_symtab` function, which may lead to an application crash and local denial of service.

1 affected package

binutils

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
binutils Fixed Fixed Fixed
Show less packages

CVE-2023-25586

Medium priority
Not affected

A flaw was found in Binutils. A logic fail in the bfd_init_section_decompress_status function may lead to the use of an uninitialized variable that can cause a crash and local denial of service.

1 affected package

binutils

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
binutils Not affected Not affected Not affected
Show less packages

CVE-2023-25585

Medium priority
Fixed

A flaw was found in Binutils. The use of an uninitialized field in the struct module *module may lead to application crash and local denial of service.

1 affected package

binutils

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
binutils Fixed Fixed Fixed
Show less packages

CVE-2023-25584

Medium priority

Some fixes available 4 of 6

An out-of-bounds read flaw was found in the parse_module function in bfd/vms-alpha.c in Binutils.

1 affected package

binutils

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
binutils Fixed Fixed Fixed
Show less packages

CVE-2023-22609

Low priority
Not affected

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

1 affected package

binutils

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
binutils Not affected Not affected Not affected
Show less packages