Insecure digital certificates In gnutls28
Description
A flaw was found in gnutls. When validating certificates, an oversized Subject Alternative Name (SAN) could cause the validation process to incorrectly fall back to checking the Common Name (CN) field. This could allow a remote attacker to bypass proper certificate validation, potentially leading to spoofing or man-in-the-middle attacks.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
debian 11 | 3.7.1-5+deb11u10 | ||
debian 13 | 3.8.9-3+deb13u4 | ||
debian 14 | 3.8.13-1 | ||
alpine v3.20 | 3.8.13-r0 | ||
alpine v3.21 | 3.8.13-r0 | ||
alpine v3.22 | 3.8.13-r0 | ||
alpine v3.23 | 3.8.13-r0 | ||
rpm rhel10 | 0:3.8.10-4.el10_2 | ||
rpm rhel6 | - | - | |
rpm rhel7 | - | - |
1-10 of 20
10
Aliases
1. 2. 3. 4. 5. 6. 7.