GnuTLS certificate verification Security Restriction Bypass Vulnerability (CVE-2015-0282)
Release date:
Updated on:
Affected Systems:
GNU GnuTLS <3.1.0
Description:
Bugtraq id: 73119
CVE (CAN) ID: CVE-2015-0282
GnuTLS is a function library used to implement TLS encryption.
GnuTLS does not verify that the rsa pkcs #1 Signature Algorithm matches the signature algorithm of the certificate, which can be used to sign the certificate with a low-level or even disabled algorithm.
<* Source: vendor
Link: http://www.securityfocus.com/archive/1/534889
*>
Suggestion:
Vendor patch:
GNU
---
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.gnu.org
GnuTLS details: click here
GnuTLS: click here
JSSE works with GnuTLS to implement secure communication between Java and C.
Install GnuTLS in Mac OS X 10.6
Compile and install the new GnuTLS version in CentOS
This article permanently updates the link address: