mod-gnutls does not validate client certificates when GnuTLSClientVerify require is set in a directory context, which allows remote attackers to spoof clients via a crafted certificate.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Mod_gnutls | Mod_gnutls_project | - (including) | - (including) |
| Mod-gnutls | Ubuntu | lucid | * |
| Mod-gnutls | Ubuntu | upstream | * |