CVE-2024-45289: Freebsd
High severity, CVSS 7.5. EPSS: 0.3% chance of exploitation in the next 30 days.
The fetch(3) library uses environment variables for passing certain information, including the revocation file pathname. The environment variable name used by fetch(1) to pass the filename to the library was incorrect, in effect ignoring the option. Fetch would still connect to a host presenting a certificate included in the revocation file passed to the --crl option.
Affected products
- Freebsd Freebsd: from 14.1-RELEASE, before p6 (fixed in p6); from 13.4-RELEASE, before p2 (fixed in p2); from 13.3-RELEASE, before p8 (fixed in p8); from 14.1-release, before p6 (fixed in p6); from 13.4-release, before p2 (fixed in p2); from 13.3-release, before p8 (fixed in p8)
Published 2024-11-12. Last modified 2026-06-17.