CVE-2009-5144: High severity gnutls vulnerability
It was reported that under certain conditions modgnutls ignores "GnuTLSClientVerify require" when specified in directory [1] and server [2] context. Suggested commit that fixes [2] is: https://github.com/airtower-luna/modgnutls/commit/5a8a32bbfb8a83fe6358c5c31c443325a7775fc2 Patch for [1] is attaced in the corresponding bugreport.
[1]: http://issues.outoforder.cc/view.php?id=93 [2]: https://bugs.debian.org/578663
Other sources
mod-gnutls does not validate client certificates when "GnuTLSClientVerify require" is set in a directory context, which allows remote attackers to spoof clients via a crafted certificate.
— MITRE
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-5144?
CVE-2009-5144 has been classified as a low severity vulnerability.
How do I fix CVE-2009-5144?
To fix CVE-2009-5144, ensure that you apply the suggested commit that addresses the issue in the mod_gnutls project.
Which versions of mod_gnutls are affected by CVE-2009-5144?
CVE-2009-5144 affects all versions of mod_gnutls prior to the fix implementation.
What does CVE-2009-5144 allow an attacker to do?
CVE-2009-5144 may lead to improper verification of client certificates, potentially allowing unauthorized access.
Is CVE-2009-5144 related to any specific operating systems?
CVE-2009-5144 is related to the mod_gnutls module used in various server configurations and is not specific to any operating systems.