[WID-SEC-2024-0686] GnuTLS: Mehrere Schwachstellen ermöglichen Offenlegung von Informationen und DoS CVSS Base Score 7.5 (hoch) CVSS Temporal Score 6.5 (mittel) Remoteangriff ja Datum 20.03.2024 Stand UPDATE 01.09.2026 Mitigation ja Betroffene Systeme Betriebssystem UNIX Windows Produktbeschreibung GnuTLS (GNU Transport Layer Security Library) ist eine im Quelltext frei verfügbare Bibliothek, die Secure Sockets Layer (SSL) und Transport Layer Security (TLS) implementiert. Produkte UPDATE 31.08.2026 Dell Secure Connect Gateway <5.36.00.16 UPDATE 12.01.2025 Xerox FreeFlow Print Server v9 for Solaris UPDATE 08.01.2025 Juniper Junos Space <24.1R2 UPDATE 31.10.2024 IBM QRadar SIEM <7.5.0 UP10 IF01 UPDATE 23.10.2024 IBM Security Guardium 12.0 UPDATE 04.09.2024 Debian Linux UPDATE 04.08.2024 IBM MQ UPDATE 11.07.2024 IBM QRadar SIEM <7.5.0 UP9 UPDATE 02.06.2024 IBM App Connect Enterprise <11.6.0 IBM App Connect Enterprise LTS <5.0.18 UPDATE 21.05.2024 IBM MQ Operator <3.1.3 IBM MQ Operator <2.0.22 LTS UPDATE 20.05.2024 Red Hat Enterprise Linux Advanced Cluster Security for Kubernetes 4 UPDATE 06.05.2024 RESF Rocky Linux UPDATE 15.04.2024 Ubuntu Linux Oracle Linux UPDATE 14.04.2024 SUSE Linux UPDATE 11.04.2024 Red Hat Enterprise Linux 20.03.2024 Open Source GnuTLS <3.8.4 Angriff Angriff Ein Angreifer kann mehrere Schwachstellen in GnuTLS ausnutzen, um Informationen offenzulegen oder einen Denial-of-Service-Zustand zu verursachen. CVE Informationen Versionshistorie Feedback zum Advisory geben
Multiple vulnerabilities in GnuTLS (CVE not specified) can be exploited remotely to cause information disclosure or a denial-of-service condition, with a CVSS base score of 7.5 (High). The core library vulnerability affects GnuTLS versions prior to 3.8.4. The advisory recommends applying available patches, as evidenced by the extensive list of updated vendor products and operating systems.