GnuTLS before 3.3.13 does not validate that the signature algorithms match when importing a certificate.
The product does not validate, or incorrectly validates, a certificate.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Gnutls | Gnu | * | 3.3.13 (excluding) |
Red Hat Enterprise Linux 6 | RedHat | gnutls-0:2.8.5-18.el6 | * |
Gnutls26 | Ubuntu | lucid | * |
Gnutls26 | Ubuntu | precise | * |
Gnutls26 | Ubuntu | trusty | * |
Gnutls26 | Ubuntu | utopic | * |
Gnutls28 | Ubuntu | artful | * |
Gnutls28 | Ubuntu | bionic | * |
Gnutls28 | Ubuntu | cosmic | * |
Gnutls28 | Ubuntu | devel | * |
Gnutls28 | Ubuntu | disco | * |
Gnutls28 | Ubuntu | precise | * |
Gnutls28 | Ubuntu | trusty | * |
Gnutls28 | Ubuntu | upstream | * |
Gnutls28 | Ubuntu | utopic | * |
Gnutls28 | Ubuntu | vivid | * |
Gnutls28 | Ubuntu | vivid/stable-phone-overlay | * |
Gnutls28 | Ubuntu | vivid/ubuntu-core | * |
Gnutls28 | Ubuntu | wily | * |
Gnutls28 | Ubuntu | xenial | * |
Gnutls28 | Ubuntu | yakkety | * |
Gnutls28 | Ubuntu | zesty | * |