[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247768

 
 

909

 
 

194555

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2008-4989Date: (C)2008-11-12   (M)2024-02-22


The _gnutls_x509_verify_certificate function in lib/x509/verify.c in libgnutls in GnuTLS before 2.6.1 trusts certificate chains in which the last certificate is an arbitrary trusted, self-signed certificate, which allows man-in-the-middle attackers to insert a spoofed certificate for any Distinguished Name (DN).

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V3 Severity:CVSS V2 Severity:
CVSS Score : 5.9CVSS Score : 4.3
Exploit Score: 2.2Exploit Score: 8.6
Impact Score: 3.6Impact Score: 2.9
 
CVSS V3 Metrics:CVSS V2 Metrics:
Attack Vector: NETWORKAccess Vector: NETWORK
Attack Complexity: HIGHAccess Complexity: MEDIUM
Privileges Required: NONEAuthentication: NONE
User Interaction: NONEConfidentiality: NONE
Scope: UNCHANGEDIntegrity: PARTIAL
Confidentiality: NONEAvailability: NONE
Integrity: HIGH 
Availability: NONE 
  
Reference:
SECTRACK-1021167
http://www.securityfocus.com/archive/1/498431/100/0/threaded
SUNALERT-260528
BID-32232
SECUNIA-32619
SECUNIA-32681
SECUNIA-32687
SECUNIA-32879
SECUNIA-33501
SECUNIA-33694
SECUNIA-35423
ADV-2008-3086
ADV-2009-1567
DSA-1719
FEDORA-2008-9530
FEDORA-2008-9600
GLSA-200901-10
MDVSA-2008:227
RHSA-2008:0982
SUSE-SR:2008:027
SUSE-SR:2009:009
USN-678-1
USN-678-2
http://article.gmane.org/gmane.comp.encryption.gpg.gnutls.devel/3217
http://article.gmane.org/gmane.comp.encryption.gpg.gnutls.devel/3215
gnutls-x509-name-spoofing(46482)
http://wiki.rpath.com/Advisories:rPSA-2008-0322
http://www.gnu.org/software/gnutls/security.html
https://issues.rpath.com/browse/RPL-2886
oval:org.mitre.oval:def:11650

CWE    1
CWE-295
OVAL    8
oval:org.secpod.oval:def:202673
oval:org.secpod.oval:def:600479
oval:org.secpod.oval:def:301477
oval:org.secpod.oval:def:101826
...

© SecPod Technologies