GnuTLS
cpe:2.3:a:gnu:gnutls:*:*:*:*:*:*:*
- <= 10
- <= 6
- <= 7
- <= 8
- <= 9
A vulnerability in GnuTLS allows for a certificate validation bypass. When processing certificates, an oversized Subject Alternative Name (SAN) can cause the validation to incorrectly revert to the Common Name (CN) field. This flaw could enable a remote attacker to evade proper certificate checks, potentially leading to spoofing or man-in-the-middle attacks.
Exploitation of this vulnerability could result in improper certificate validation, allowing for spoofing or man-in-the-middle attacks.
This vulnerability can be reproduced by using a certificate that has an oversized Subject Alternative Name. During the validation process, GnuTLS will incorrectly fall back to checking the Common Name field, bypassing the usual certificate validation procedures.
Users can update to the latest version of GnuTLS where this issue has been fixed. Red Hat users should refer to the Red Hat Security Errata for guidance on updating.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.