CVE-2008-4989: Medium severity gnutls vulnerability
The gnutlsx509verifycertificate function in lib/x509/verify.c in libgnutls in GnuTLS before 2.6.1 trusts certificate chains in which the last certificate is an arbitrary trusted, self-signed certificate, which allows man-in-the-middle attackers to insert a spoofed certificate for any Distinguished Name (DN).
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2008-4989?
CVE-2008-4989 is classified as a high-severity vulnerability due to its potential for man-in-the-middle attacks.
How do I fix CVE-2008-4989?
To fix CVE-2008-4989, upgrade GnuTLS to version 2.6.1 or later.
What type of attack can exploit CVE-2008-4989?
CVE-2008-4989 can be exploited to perform man-in-the-middle attacks using spoofed certificates.
Which versions of GnuTLS are affected by CVE-2008-4989?
GnuTLS versions prior to 2.6.1, specifically versions 1.0.16 to 2.6.0, are affected by CVE-2008-4989.
Is CVE-2008-4989 relevant to specific operating systems?
CVE-2008-4989 is relevant to any operating system that utilizes the vulnerable versions of GnuTLS.