In ca-certificates, there is a possible way to read encrypted TLS data due to untrusted cryptographic certificates. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: google_android

Published: 2024-02-15T22:31:14.778Z

Updated: 2024-08-02T18:24:55.545Z

Reserved: 2023-08-09T02:29:31.021Z

Link: CVE-2023-40104

cve-icon Vulnrichment

Updated: 2024-08-02T18:24:55.545Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-02-15T23:15:08.017

Modified: 2024-08-01T13:44:27.157

Link: CVE-2023-40104

cve-icon Redhat

No data.