vulnerability
FreeBSD: VID-2272e6f1-f029-11ea-838a-0011d823eebd (CVE-2020-24659): GnuTLS -- null pointer dereference
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 5 | (AV:N/AC:L/Au:N/C:N/I:N/A:P) | Sep 6, 2020 | Sep 7, 2020 | Dec 10, 2025 |
Severity
5
CVSS
(AV:N/AC:L/Au:N/C:N/I:N/A:P)
Published
Sep 6, 2020
Added
Sep 7, 2020
Modified
Dec 10, 2025
Description
The GnuTLS project reports: It was found by oss-fuzz that the server sending a "no_renegotiation" alert in an unexpected timing, followed by an invalid second handshake can cause a TLS 1.3 client to crash via a null-pointer dereference. The crash happens in the application's error handling path, where the gnutls_deinit function is called after detecting a handshake failure.
Solution
freebsd-upgrade-package-gnutls
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.