vulnerability
FreeBSD: VID-ce0f52e1-a174-11ef-9a62-002590c1f29c (CVE-2024-45289): FreeBSD -- Certificate revocation list fetch(1) option fails
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 8 | (AV:N/AC:L/Au:N/C:C/I:N/A:N) | Nov 13, 2024 | Nov 14, 2024 | Dec 10, 2025 |
Severity
8
CVSS
(AV:N/AC:L/Au:N/C:C/I:N/A:N)
Published
Nov 13, 2024
Added
Nov 14, 2024
Modified
Dec 10, 2025
Description
Problem Description: The fetch(3) library uses environment variables for passing certain information, including the revocation file pathname. The environment variable name used by fetch(1) to pass the filename to the library was incorrect, in effect ignoring the option. Impact: Fetch would still connect to a host presenting a certificate included in the revocation file passed to the --crl option.
Solutions
freebsd-upgrade-base-14_1-release-p6freebsd-upgrade-base-13_4-release-p2freebsd-upgrade-base-13_3-release-p8
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.