[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250053

 
 

909

 
 

195940

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

CESA-2009:1232 -- centos 4 i386 gnutls

ID: oval:org.secpod.oval:def:202736Date: (C)2013-05-08   (M)2022-10-10
Class: PATCHFamily: unix




The GnuTLS library provides support for cryptographic algorithms and for protocols such as Transport Layer Security . A flaw was discovered in the way GnuTLS handles NULL characters in certain fields of X.509 certificates. If an attacker is able to get a carefully-crafted certificate signed by a Certificate Authority trusted by an application using GnuTLS, the attacker could use the certificate during a man-in-the-middle attack and potentially confuse the application into accepting it by mistake. Users of GnuTLS are advised to upgrade to these updated packages, which contain a backported patch that corrects this issue.

Platform:
CentOS 4
Product:
gnutls
Reference:
CESA-2009:1232
CVE-2009-2730
CVE    1
CVE-2009-2730
CPE    1
cpe:/o:centos:centos:4

© SecPod Technologies