LWN.net Logo

gnutls: certificate spoofing vulnerability

Package(s):gnutls12, gnutls13, gnutls26 CVE #(s):CVE-2009-2730
Created:August 20, 2009 Updated:February 16, 2010
Description: From the National Vulnerability Database entry: "libgnutls in GnuTLS before 2.8.2 does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) or Subject Alternative Name (SAN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority."
Alerts:
Gentoo 201110-05 2011-10-10
Mandriva MDVSA-2009:308 2009-12-03
SuSE SUSE-SR:2010:004 2010-02-16
Fedora FEDORA-2009-8565 2009-08-15
Fedora FEDORA-2009-8622 2009-08-15
SuSE SUSE-SR:2009:015 2009-09-15
CentOS CESA-2009:1232 2009-08-26
CentOS CESA-2009:123 2009-08-26
Red Hat RHSA-2009:1232-01 2009-08-26
Mandriva MDVSA-2009:210 2009-08-20
Ubuntu USN-809-1 2009-08-19
Debian DSA-1935-1 2009-11-17
Slackware SSA:2009-290-01 2009-10-19
Gentoo 201206-18 2012-06-23

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds