GnuTLS Certificate Verification Vulnerability
Last Update Date:
6 Mar 2014 12:13
Release Date:
6 Mar 2014
4209
Views
RISK: Medium Risk
TYPE: Security software and application - Security Software & Appliance

A vulnerability has been identified in GnuTLS, which affects certificate verification functions. An attacker could use a specially crafted X509 certificate to bypass validation checks, impersonate legitimate web sites or services, and perform man-in-the-middle attacks.
Impact
- Security Restriction Bypass
- Spoofing
System / Technologies affected
- Many Linux distributions and other software which use GnuTLS are affected.
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Updates available include:
- GnuTLS 2.12.x patch application
- GnuTLS 3.2.12 for the current stable branch
- GnuTLS 3.1.22 for the previous stable branch
Vulnerability Identifier
Source
Related Link
Share with