gnutls: certificate spoofing vulnerability
| Package(s): | gnutls12, gnutls13, gnutls26 |
CVE #(s): | CVE-2009-2730
|
| Created: | August 20, 2009 |
Updated: | February 16, 2010 |
| Description: |
From the National Vulnerability Database
entry:
"libgnutls in GnuTLS before 2.8.2 does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) or Subject Alternative Name (SAN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority. " |
| Alerts: |
| Gentoo |
201206-18 |
gnutls |
2012-06-23 |
| Gentoo |
201110-05 |
gnutls |
2011-10-10 |
| Mandriva |
MDVSA-2009:308 |
gnutls |
2009-12-03 |
| SuSE |
SUSE-SR:2010:004 |
moodle, xpdf, pdns-recursor, pango, horde, gnome-screensaver, fuse, gnutls, flash-player |
2010-02-16 |
| Fedora |
FEDORA-2009-8565 |
gnutls |
2009-08-15 |
| Fedora |
FEDORA-2009-8622 |
gnutls |
2009-08-15 |
| SuSE |
SUSE-SR:2009:015 |
OpenOffice_org, OpenOffice_org-math, dnsmasq, gnutls, ia32el, ib-bonding-kmp-rt/kernel-rt, libxml, opera, perl-IO-Socket-SSL, xen |
2009-09-15 |
| CentOS |
CESA-2009:1232 |
gnutls |
2009-08-26 |
| CentOS |
CESA-2009:123 |
gnutls |
2009-08-26 |
| Red Hat |
RHSA-2009:1232-01 |
gnutls |
2009-08-26 |
| Mandriva |
MDVSA-2009:210 |
gnutls |
2009-08-20 |
| Ubuntu |
USN-809-1 |
gnutls12, gnutls13, gnutls26 |
2009-08-19 |
| Debian |
DSA-1935-1 |
gnutls13 |
2009-11-17 |
| Slackware |
SSA:2009-290-01 |
gnutls |
2009-10-19 |
|