|
GnuTLS X.509 Certificate Chain Security Bypass Vulnerability
GnuTLS is prone to a security-bypass vulnerability because the application fails to properly validate chained X.509 certificates. Successfully exploiting this issue allows attackers to perform man-in-the-middle attacks by impersonating trusted servers. Unsuspecting users may be under a false sense of security that can aid attackers in launching further attacks. Versions prior to GnuTLS 2.6.1 are vulnerable. |
|
|
Privacy Statement |