Get a Pentest and security assessment of your IT network.

Advisories

Mandriva Linux Security Advisory 2009-308

Mandriva Linux Security Advisory 2009-308 – gnutls-cli in GnuTLS before 2.6.6 does not verify the activation and expiration times of X.509 certificates, which allows remote attackers to successfully present a certificate that is (1) not yet valid or (2) no longer valid, related to lack of time checks in the _gnutls_x509_verify_certificate function in lib/x509/verify.c in libgnutls_x509, as used by (a) Exim, (b) OpenLDAP, and (c) libsoup. A vulnerability have been discovered and corrected in GnuTLS before 2.8.2, which could allow man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority. Packages for 2008.0 are being provided due to extended support for Corporate products. This update fixes this vulnerability.

 

You can download this advisory from the following link: https://packetstormsecurity.com/files/download/83404/MDVSA-2009-308.txt

Source: https://packetstormsecurity.com/files/83404/Mandriva-Linux-Security-Advisory-2009-308.html

Related posts
Advisories

CSIS2005-1.txt

Advisories

Secunia Security Advisory 17625

Advisories

Secunia Security Advisory 20411

Advisories

Secunia Security Advisory 23300