Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:11175
HistoryJan 15, 2019 - 8:58 a.m.

Man-in-the-Middle (MitM)

2019-01-1508:58:04
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
17

0.075 Low

EPSS

Percentile

94.1%

gnutls is vulnerable to man-in-the-middle (MitM) attacks. The vulnerability exists as lib/x509/verify.c in GnuTLS before 3.1.22 and 3.2.x before 3.2.12 does not properly handle unspecified errors when verifying X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers via a crafted certificate.

References