Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2009-5144

Опубликовано: 03 фев. 2018
Источник: nvd
CVSS3: 7.5
CVSS2: 5
EPSS Низкий

Описание

mod-gnutls does not validate client certificates when "GnuTLSClientVerify require" is set in a directory context, which allows remote attackers to spoof clients via a crafted certificate.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:mod_gnutls_project:mod_gnutls:-:*:*:*:*:*:*:*

EPSS

Процентиль: 38%
0.00163
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-254

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 8 лет назад

mod-gnutls does not validate client certificates when "GnuTLSClientVerify require" is set in a directory context, which allows remote attackers to spoof clients via a crafted certificate.

CVSS3: 7.5
debian
почти 8 лет назад

mod-gnutls does not validate client certificates when "GnuTLSClientVer ...

CVSS3: 7.5
github
больше 3 лет назад

mod-gnutls does not validate client certificates when "GnuTLSClientVerify require" is set in a directory context, which allows remote attackers to spoof clients via a crafted certificate.

EPSS

Процентиль: 38%
0.00163
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-254