Back to search
CVE-2009-5144
Published: Feb 3, 2018
Modified: Aug 7, 2024
PUBLISHED
Description
mod-gnutls does not validate client certificates when "GnuTLSClientVerify require" is set in a directory context, which allows remote attackers to spoof clients via a crafted certificate.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
http://issues.outoforder.cc/view.php?id=93
x_refsource_CONFIRM
https://bugzilla.redhat.com/show_bug.cgi?id=1197127
x_refsource_CONFIRM
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=578663
x_refsource_CONFIRM
[oss-security] 20150226 Re: CVE Request: mod-gnutls: GnuTLSClientVerify require is ignored
mailing-list
x_refsource_MLIST
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now