Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c9fv-cm23-r7xv

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

lib/x509/verify.c in GnuTLS before 3.1.22 and 3.2.x before 3.2.12 does not properly handle unspecified errors when verifying X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers via a crafted certificate.

lib/x509/verify.c in GnuTLS before 3.1.22 and 3.2.x before 3.2.12 does not properly handle unspecified errors when verifying X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers via a crafted certificate.

EPSS

Процентиль: 87%
0.03379
Низкий

Связанные уязвимости

ubuntu
больше 11 лет назад

lib/x509/verify.c in GnuTLS before 3.1.22 and 3.2.x before 3.2.12 does not properly handle unspecified errors when verifying X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers via a crafted certificate.

redhat
больше 11 лет назад

lib/x509/verify.c in GnuTLS before 3.1.22 and 3.2.x before 3.2.12 does not properly handle unspecified errors when verifying X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers via a crafted certificate.

nvd
больше 11 лет назад

lib/x509/verify.c in GnuTLS before 3.1.22 and 3.2.x before 3.2.12 does not properly handle unspecified errors when verifying X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers via a crafted certificate.

debian
больше 11 лет назад

lib/x509/verify.c in GnuTLS before 3.1.22 and 3.2.x before 3.2.12 does ...

oracle-oval
больше 11 лет назад

ELSA-2014-0246: gnutls security update (IMPORTANT)

EPSS

Процентиль: 87%
0.03379
Низкий