CVEs Blog | G5 Cyber Security

CVE-2015-2091 – The authentication hook (mgs_hook_authz) in mod-gnutls 0.5.10 and earlier

The authentication hook (mgs_hook_authz) in mod-gnutls 0.5.10 and earlier does not validate client certificates when “GnuTLSClientVerify require” is set, which allows remote attackers to spoof clients via a crafted certificate.

 

Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2091

Reference (s):

Exit mobile version