mod-gnutls does not validate client certificates when GnuTLSClientVerify require is set in a directory context, which allows remote attackers to spoof clients via a crafted certificate.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Mod_gnutls | Mod_gnutls_project | - (including) | - (including) |
Mod-gnutls | Ubuntu | lucid | * |
Mod-gnutls | Ubuntu | upstream | * |