gnutls: certificate verification bypass
| Package(s): | gnutls | CVE #(s): | CVE-2016-7444 | ||||||||||||||||||||||||||||||||
| Created: | September 14, 2016 | Updated: | September 28, 2016 | ||||||||||||||||||||||||||||||||
| Description: | From the Red Hat bugzilla:
It was found an issue in certificate validation using OCSP responses caused by not verifying the serial length, which can falsely report a certificate as valid. See the CVE assignment for more information. | ||||||||||||||||||||||||||||||||||
| Alerts: |
| ||||||||||||||||||||||||||||||||||
