CVE-2008-4989
Summary
The _gnutls_x509_verify_certificate function in lib/x509/verify.c in libgnutls in GnuTLS before 2.6.1 trusts certificate chains in which the last certificate is an arbitrary trusted, self-signed certificate, which allows man-in-the-middle attackers to insert a spoofed certificate for any Distinguished Name (DN).
Impact & exploitability
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Affected products we track (3)
Recommendation
Apply the vendor fix in your normal patch cycle. Open any affected product above for its exact safe version.
Official patch: http://article.gmane.org/gmane.comp.encryption.gpg.gnutls.devel/3215 ↗
Additional information
- NVD record
- http://article.gmane.org/gmane.comp.encryption.gpg.gnutls.devel/3215Patch
- http://secunia.com/advisories/32619Advisory
- http://article.gmane.org/gmane.comp.encryption.gpg.gnutls.devel/3217
- http://lists.opensuse.org/opensuse-security-announce/2008-12/msg00002.html
- http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00010.html
- http://secunia.com/advisories/32681
- http://secunia.com/advisories/32687
- http://secunia.com/advisories/32879