VDB

GCVE-VVD-MAGEIA-2024-31

GCVE-VVD-MAGEIA-2024-31
Advisory Published
Vulnetix · Advisory published January 30, 2024
The updated packages fix security vulnerabilities: A vulnerability was found in GnuTLS, where a cockpit (which uses gnuTLS) rejects a certificate chain with distributed trust. This issue occurs when validating a certificate chain with cockpit-certificate-ensure. This flaw allows an unauthenticated, remote client or attacker to initiate a denial of service attack. (CVE-2024-0567) A vulnerability was found in GnuTLS. The response times to malformed ciphertexts in RSA-PSK ClientKeyExchange differ from response times of ciphertexts with correct PKCS#1 v1.5 padding. This issue may allow a remote attacker to perform a timing side-channel attack in the RSA-PSK key exchange, potentially leading to the leakage of sensitive data. CVE-2024-0553 is designated as an incomplete resolution for CVE-2023-5981. (CVE-2024-0553)

Affected Products

VendorProductVersionsPlatforms
Mageiavirtualbox0 (affected), 7.0.14-1.mga9 (unaffected)
Mageiakmod-virtualbox0 (affected), 7.0.14-41.mga9 (unaffected)
Mageiagnutls0 (affected), 3.8.0-2.2.mga9 (unaffected), 0 (affected), 3.8.0-2.2.mga9 (unaffected)

Browse GCVE Records

100 records in the GCVE database · Updated April 16, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›