|
|
Log in / Subscribe / Register

gnutls: man in the middle attacks

Package(s):gnutls CVE #(s):CVE-2008-4989
Created:November 11, 2008 Updated:September 28, 2009
Description: From the Red Hat advisory: Martin von Gagern discovered a flaw in the way GnuTLS verified certificate chains provided by a server. A malicious server could use this flaw to spoof its identity by tricking client applications using the GnuTLS library to trust invalid certificates.
Alerts:
Fedora FEDORA-2009-8622 gnutls 2009-08-15
Ubuntu USN-809-1 gnutls12, gnutls13, gnutls26 2009-08-19
SuSE SUSE-SR:2009:009 openswan/strongswan, clamav, gstreamer-0_10-plugins-base, gnome-panel, postgresql, acroread_ja, ghostscript-devel, xine-devel/libxine-devel, moodle, gnutls, udev 2009-04-21
Debian DSA-1719-2 gnutls13 2009-02-28
Debian DSA-1719-1 gnutls13 2009-02-10
Gentoo 200901-10 gnutls 2009-01-14
Ubuntu USN-678-2 gnutls 2008-12-10
SuSE SUSE-SR:2008:027 squirrelmail, gnutls, rubygem-activerecord, rubygem-actionpack, samba, dbus-1, pdns, php5, pam_krb5 2008-12-09
Ubuntu USN-678-1 gnutls12, gnutls13, gnutls26 2008-11-26
Fedora FEDORA-2008-10000 gnutls 2008-11-22
Mandriva MDVSA-2008:227-1 gnutls 2008-11-17
rPath rPSA-2008-0322-1 gnutls 2008-11-17
Slackware SSA:2008-320-01 gnutls 2008-11-17
Mandriva MDVSA-2008:227 gnutls 2008-11-12
Fedora FEDORA-2008-9530 gnutls 2008-11-12
Fedora FEDORA-2008-9600 gnutls 2008-11-12
CentOS CESA-2008:0982 gnutls 2008-11-11
Slackware SSA:2008-315-01 gnutls 2008-11-11
Red Hat RHSA-2008:0982-01 gnutls 2008-11-11

to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds