gnutls: man in the middle attacks
| Package(s): | gnutls |
CVE #(s): | CVE-2008-4989
|
| Created: | November 11, 2008 |
Updated: | September 28, 2009 |
| Description: |
From the Red Hat advisory: Martin von Gagern discovered a flaw in the way GnuTLS verified certificate chains provided by a server. A malicious server could use this flaw to spoof its identity by tricking client applications using the GnuTLS library to trust invalid certificates. |
| Alerts: |
| Fedora |
FEDORA-2009-8622 |
gnutls |
2009-08-15 |
| Ubuntu |
USN-809-1 |
gnutls12, gnutls13, gnutls26 |
2009-08-19 |
| SuSE |
SUSE-SR:2009:009 |
openswan/strongswan, clamav, gstreamer-0_10-plugins-base, gnome-panel, postgresql, acroread_ja, ghostscript-devel, xine-devel/libxine-devel, moodle, gnutls, udev |
2009-04-21 |
| Debian |
DSA-1719-2 |
gnutls13 |
2009-02-28 |
| Debian |
DSA-1719-1 |
gnutls13 |
2009-02-10 |
| Gentoo |
200901-10 |
gnutls |
2009-01-14 |
| Ubuntu |
USN-678-2 |
gnutls |
2008-12-10 |
| SuSE |
SUSE-SR:2008:027 |
squirrelmail, gnutls, rubygem-activerecord, rubygem-actionpack, samba, dbus-1, pdns, php5, pam_krb5 |
2008-12-09 |
| Ubuntu |
USN-678-1 |
gnutls12, gnutls13, gnutls26 |
2008-11-26 |
| Fedora |
FEDORA-2008-10000 |
gnutls |
2008-11-22 |
| Mandriva |
MDVSA-2008:227-1 |
gnutls |
2008-11-17 |
| rPath |
rPSA-2008-0322-1 |
gnutls |
2008-11-17 |
| Slackware |
SSA:2008-320-01 |
gnutls |
2008-11-17 |
| Mandriva |
MDVSA-2008:227 |
gnutls |
2008-11-12 |
| Fedora |
FEDORA-2008-9530 |
gnutls |
2008-11-12 |
| Fedora |
FEDORA-2008-9600 |
gnutls |
2008-11-12 |
| CentOS |
CESA-2008:0982 |
gnutls |
2008-11-11 |
| Slackware |
SSA:2008-315-01 |
gnutls |
2008-11-11 |
| Red Hat |
RHSA-2008:0982-01 |
gnutls |
2008-11-11 |
|