GnuTLS before 2.9.10 does not verify the activation and expiration dates of CA certificates, which allows man-in-the-middle attackers to spoof servers via a certificate issued by a CA certificate that is (1) not yet valid or (2) no longer valid.
CVSS Details
- CVSS 3.1 Base Score: 3.7
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| F5 Big Ip | — | — | Apr 9, 2019 | Aug 14, 2015 |
| Oracle_linux | — | Upgrade gnutls-develUpgrade gnutls-guileUpgrade gnutlsUpgrade gnutls-utils | Oct 16, 2024 | Aug 14, 2015 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Mar 14, 2010 |
| Suse | — | Upgrade libgnutls26-32bitUpgrade libgnutls-develUpgrade libgnutls-extra26Upgrade gnutlsUpgrade libgnutls26Upgrade libgnutls26-x86Upgrade libgnutls-extra-devel | Dec 18, 2015 | Apr 7, 2015 |
| Ubuntu | — | Upgrade libgnutls-deb0-28Upgrade libgnutls26 | Nov 8, 2024 | Aug 14, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub