info
discussion
exploit
solution
references
GnuTLS NULL Character CA SSL Certificate Validation Security Bypass Vulnerability
References:
[Help-gnutls] NUL bytes in X.509 CN/SAN fields [GNUTLS-SA-2009-4] [CVE-2009-2730
(Simon Josefsson)
ASA-2009-385
(Avaya)
GnuTLS 2.8.2
(Simon Josefsson)
GnuTLS CVE-2009-2730 Patches (Was Re: GnuTLS 2.8.2)
(Jamie Strandboge)
GnuTLS Homepage
(GNU)
GnuTLS vs. NULL chars in CNs
(Tomas Hoger)
How to check if your GnuTLS is vulnerable to NUL-in-CN/SAN issue
(Simon Josefsson)
Re: CVE request: fetchmail <= 6.3.10 SSL certificate NUL prefix verification byp
(Tomas Hoger)
Privacy Statement
Copyright 2010, SecurityFocus