Skip to main content

GnuTLS Certificate Verification Vulnerability

Last Update Date: 6 Mar 2014 12:13 Release Date: 6 Mar 2014 2953 Views

RISK: Medium Risk

TYPE: Security software and application - Security Software & Appliance

TYPE: Security Software & Appliance

A vulnerability has been identified in GnuTLS, which affects certificate verification functions. An attacker could use a specially crafted X509 certificate to bypass validation checks, impersonate legitimate web sites or services, and perform man-in-the-middle attacks.


Impact

  • Security Restriction Bypass
  • Spoofing

System / Technologies affected

  • Many Linux distributions and other software which use GnuTLS are affected.

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

  • Updates available include:
    • GnuTLS 2.12.x patch application
    • GnuTLS 3.2.12 for the current stable branch
    • GnuTLS 3.1.22 for the previous stable branch

Vulnerability Identifier


Source


Related Link