|
|
Log in / Subscribe / Register

gnutls: certificate verification bypass

Package(s):gnutls CVE #(s):CVE-2016-7444
Created:September 14, 2016 Updated:September 28, 2016
Description: From the Red Hat bugzilla:

It was found an issue in certificate validation using OCSP responses caused by not verifying the serial length, which can falsely report a certificate as valid.

See the CVE assignment for more information.

Alerts:
Mageia MGASA-2016-0326 gnutls 2016-09-28
Arch Linux ASA-201609-26 lib32-gnutls 2016-09-26
Arch Linux ASA-201609-25 gnutls 2016-09-26
Fedora FEDORA-2016-2edb9adec8 gnutls 2016-09-14
Fedora FEDORA-2016-e1589894e8 gnutls 2016-09-13
openSUSE openSUSE-SU-2017:0386-1 gnutls 2017-02-04
Ubuntu USN-3183-1 gnutls26, gnutls28 2017-02-01
SUSE SUSE-SU-2017:0348-1 gnutls 2017-02-01

to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds