Mandriva Linux Security Advisory – Martin von Gagern found a flow in how GnuTLS versions 1.2.4 up until 2.6.1 verified certificate chains provided by a server. A malicious server could use this flaw to spoof its identity by tricking client applications that used the GnuTLS library to trust invalid certificates. The updated packages have been patched to correct this issue.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/71925/MDVSA-2008-227.txt
Source: https://packetstormsecurity.com/files/71925/Mandriva-Linux-Security-Advisory-2008-227.html