libgnutls in GnuTLS before 2.8.2 does not properly handle a '\0' character in a domain name in the subject's (1) Common Name (CN) or (2) Subject Alternative Name (SAN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority.
CVSS Details
- CVSS 3.1 Base Score: 7.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade gnutlsUpgrade gnutls-devel | Dec 1, 2016 | Aug 12, 2009 |
| Freebsd | — | Upgrade gnutls-develUpgrade gnutls | Dec 10, 2025 | Aug 17, 2009 |
| Gentoo Linux | — | Upgrade net-libs/gnutls. | Oct 30, 2017 | Aug 12, 2009 |
| Oracle Solaris | — | Upgrade library/gnutls to version 2.8.6-0.175.1.8.0.2.0 on Solaris 11.1Upgrade consolidation/desktop/desktop-incorporation to version 0.5.11-0.175.2.0.0.42.0 on Solaris 11.2 | May 29, 2017 | Aug 12, 2009 |
| Oracle_linux | — | Upgrade gnutls-utilsUpgrade gnutls-develUpgrade gnutls | Oct 16, 2024 | Aug 12, 2009 |
| Suse | — | Upgrade gnutlsUpgrade libgnutls-develUpgrade libgnutls26Upgrade libgnutls-extra-develUpgrade libgnutls-extra26Upgrade libgnutls26-x86Upgrade libgnutls26-32bit | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade libgnutls12Upgrade libgnutls13Upgrade libgnutls26 | Nov 8, 2024 | Aug 12, 2009 |
| Vmsa 2009 0016 5 Updated Service Console Package Gnutls | — | Upgrade VMware ESX 4.0 to build number 208167 | Sep 2, 2010 | Aug 12, 2009 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub