Insecure digital certificates In gnutls28
Description
lib/x509/verify.c in GnuTLS before 3.1.22 and 3.2.x before 3.2.12 does not properly handle unspecified errors when verifying X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers via a crafted certificate.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
debian 11 | 3.2.11-2 | ||
debian 13 | 3.2.11-2 | ||
debian 12 | 3.2.11-2 | ||
debian 14 | 3.2.11-2 | ||
rpm rhel5 | 0:1.4.1-14.el5_10 | ||
rpm rhel5.9 | 0:1.4.1-10.el5_9.3 | ||
rpm rhel6 | 0:2.8.5-13.el6_5 | ||
rpm rhel6.4 | 0:2.8.5-10.el6_4.3 | ||
rpm rhel6 | - | - |
Aliases
1. 2. 3. 4. 5.