Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2008-4989
Description:The _gnutls_x509_verify_certificate function in lib/x509/verify.c in libgnutls in GnuTLS before 2.6.1 trusts certificate chains in which the last certificate is an arbitrary trusted, self-signed certificate, which allows man-in-the-middle attackers to insert a spoofed certificate for any Distinguished Name (DN).
Test IDs: 1.3.6.1.4.1.25623.1.0.860058   1.3.6.1.4.1.25623.1.0.61951   1.3.6.1.4.1.25623.1.0.65842   1.3.6.1.4.1.25623.1.0.61861   1.3.6.1.4.1.25623.1.0.61811   1.3.6.1.4.1.25623.1.0.840346   1.3.6.1.4.1.25623.1.0.62923   1.3.6.1.4.1.25623.1.0.62921   1.3.6.1.4.1.25623.1.0.122543   1.3.6.1.4.1.25623.1.0.63226   1.3.6.1.4.1.25623.1.0.61971   1.3.6.1.4.1.25623.1.0.62969   1.3.6.1.4.1.25623.1.0.860874   1.3.6.1.4.1.25623.1.0.61872   1.3.6.1.4.1.25623.1.0.61841   1.3.6.1.4.1.25623.1.0.840206   1.3.6.1.4.1.25623.1.0.860508   1.3.6.1.4.1.25623.1.0.61838   1.3.6.1.4.1.25623.1.0.65653   1.3.6.1.4.1.25623.1.0.63575   1.3.6.1.4.1.25623.1.0.63392   1.3.6.1.4.1.25623.1.0.65886  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2008-4989
BugTraq ID: 32232
http://www.securityfocus.com/bid/32232
Bugtraq: 20081117 rPSA-2008-0322-1 gnutls (Google Search)
http://www.securityfocus.com/archive/1/498431/100/0/threaded
Debian Security Information: DSA-1719 (Google Search)
http://www.debian.org/security/2009/dsa-1719
https://www.redhat.com/archives/fedora-package-announce/2008-November/msg00222.html
https://www.redhat.com/archives/fedora-package-announce/2008-November/msg00293.html
http://security.gentoo.org/glsa/glsa-200901-10.xml
http://www.mandriva.com/security/advisories?name=MDVSA-2008:227
http://article.gmane.org/gmane.comp.encryption.gpg.gnutls.devel/3217
http://article.gmane.org/gmane.comp.encryption.gpg.gnutls.devel/3215
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11650
RedHat Security Advisories: RHSA-2008:0982
http://www.redhat.com/support/errata/RHSA-2008-0982.html
http://www.securitytracker.com/id?1021167
http://secunia.com/advisories/32619
http://secunia.com/advisories/32681
http://secunia.com/advisories/32687
http://secunia.com/advisories/32879
http://secunia.com/advisories/33501
http://secunia.com/advisories/33694
http://secunia.com/advisories/35423
http://sunsolve.sun.com/search/document.do?assetkey=1-26-260528-1
SuSE Security Announcement: SUSE-SR:2008:027 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2008-12/msg00002.html
SuSE Security Announcement: SUSE-SR:2009:009 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00010.html
https://usn.ubuntu.com/678-1/
http://www.ubuntu.com/usn/usn-678-2
http://www.vupen.com/english/advisories/2008/3086
http://www.vupen.com/english/advisories/2009/1567
XForce ISS Database: gnutls-x509-name-spoofing(46482)
https://exchange.xforce.ibmcloud.com/vulnerabilities/46482




© 1998-2025 E-Soft Inc. All rights reserved.