Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

GnuTLS X.509 Certificate Chain Security Bypass Vulnerability

GnuTLS is prone to a security-bypass vulnerability because the application fails to properly validate chained X.509 certificates.

Successfully exploiting this issue allows attackers to perform man-in-the-middle attacks by impersonating trusted servers. Unsuspecting users may be under a false sense of security that can aid attackers in launching further attacks.

Versions prior to GnuTLS 2.6.1 are vulnerable.







 

Privacy Statement
Copyright 2008, SecurityFocus