Wind River Support Network

HomeDefectsLIN1023-3561
Fixed

LIN1023-3561 : Security Advisory - go - CVE-2024-24783

Created: Jan 30, 2024    Updated: Mar 24, 2024
Resolved Date: Mar 24, 2024
Found In Version: 10.23.30.1
Severity: Standard
Applicable for: Wind River Linux LTS 23
Component/s: Userspace

Description

Verifying a certificate chain which contains a certificate with an unknown public key algorithm will cause Certificate.Verify to panic. This affects all crypto/tls clients, and servers that set Config.ClientAuth to VerifyClientCertIfGiven or RequireAndVerifyClientCert. The default behavior is for TLS servers to not verify client certificates.

https://nvd.nist.gov/vuln/detail/CVE-2024-24783

CVEs


Live chat
Online