The fetch(3) library uses environment variables for passing certain information, including the revocation file pathname. The environment variable name used by fetch(1) to pass the filename to the library was incorrect, in effect ignoring the option.
Fetch would still connect to a host presenting a certificate included in the revocation file passed to the --crl option.
References
Configurations
No configuration.
History
13 Nov 2024, 15:35
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
12 Nov 2024, 15:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-11-12 15:15
Updated : 2024-11-13 15:35
NVD link : CVE-2024-45289
Mitre link : CVE-2024-45289
CVE.ORG link : CVE-2024-45289
JSON object : View
Products Affected
No product.
CWE
CWE-665
Improper Initialization