GnuTLS Prior to 2.6.6 Multiple Remote Vulnerabilities

The following sites from the vendor can be used to check for the issue involving expired certificates:

Expired server certificate
https://expired.demo.gnutls.org/

Expire intermediate certificate, server return intermediate CA
https://expired-subca.demo.gnutls.org/

Expire intermediate certificate server does not return intermediate CA
https://expired-subca2.demo.gnutls.org/

The vendor has also provided tools to reproduce the memory-corruption issue related to freeing an uninitialized pointer as well as the issue involving the creation of bad keys.


 

Privacy Statement
Copyright 2010, SecurityFocus