GnuTLS before 3.3.13 does not validate that the signature algorithms match when importing a certificate.
2020-01-27T16:15:10.953
2024-11-21T02:22:45.490
Modified
CVSSv3.1: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:N/I:P/A:N
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | gnu | gnutls | < 3.3.13 | Yes |
Operating System | debian | debian_linux | 7.0 | Yes |
Operating System | redhat | enterprise_linux | 5.0 | Yes |
Operating System | redhat | enterprise_linux | 7.0 | Yes |