The fetch(3) library uses environment variables for passing certain information, including the revocation file pathname. The environment variable name used by fetch(1) to pass the filename to the library was incorrect, in effect ignoring the option. Fetch would still connect to a host presenting a certificate included in the revocation file passed to the --crl option.
History

Wed, 13 Nov 2024 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Freebsd
Freebsd freebsd
CPEs cpe:2.3:o:freebsd:freebsd:-:*:*:*:*:*:*:*
Vendors & Products Freebsd
Freebsd freebsd
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 12 Nov 2024 15:15:00 +0000

Type Values Removed Values Added
Description The fetch(3) library uses environment variables for passing certain information, including the revocation file pathname. The environment variable name used by fetch(1) to pass the filename to the library was incorrect, in effect ignoring the option. Fetch would still connect to a host presenting a certificate included in the revocation file passed to the --crl option.
Title Unbounded allocation in ctl(4) CAM Target Layer
Weaknesses CWE-665
References

cve-icon MITRE

Status: PUBLISHED

Assigner: freebsd

Published: 2024-11-12T15:06:08.435Z

Updated: 2024-11-13T14:26:36.792Z

Reserved: 2024-08-26T14:20:00.870Z

Link: CVE-2024-45289

cve-icon Vulnrichment

Updated: 2024-11-13T14:26:28.712Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-11-12T15:15:10.070

Modified: 2024-11-13T15:35:09.787

Link: CVE-2024-45289

cve-icon Redhat

No data.