The _gnutls_x509_verify_certificate function in lib/x509...
Moderate severity
Unreviewed
Published
May 14, 2022
to the GitHub Advisory Database
•
Updated Feb 18, 2024
Description
Published by the National Vulnerability Database
Nov 13, 2008
Published to the GitHub Advisory Database
May 14, 2022
Last updated
Feb 18, 2024
The _gnutls_x509_verify_certificate function in lib/x509/verify.c in libgnutls in GnuTLS before 2.6.1 trusts certificate chains in which the last certificate is an arbitrary trusted, self-signed certificate, which allows man-in-the-middle attackers to insert a spoofed certificate for any Distinguished Name (DN).
References