CVE-2015-0282: Medium severity gnutls vulnerability
Published Mar 24, 2015
·Updated
GnuTLS before 3.1.0 does not verify that the RSA PKCS #1 signature algorithm matches the signature algorithm in the certificate, which allows remote attackers to conduct downgrade attacks via unspecified vectors.
Affected Software
1 affected component
GNU GnuTLS<=3.0.9
Event History
Mar 24, 2015
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-0282?
CVE-2015-0282 is classified as a medium severity vulnerability.
2
How do I fix CVE-2015-0282?
To fix CVE-2015-0282, upgrade GnuTLS to version 3.1.0 or later.
3
What type of attacks can CVE-2015-0282 enable?
CVE-2015-0282 can allow attackers to conduct downgrade attacks.
4
Which versions of GnuTLS are affected by CVE-2015-0282?
GnuTLS versions prior to 3.1.0 are affected by CVE-2015-0282.
5
What component of GnuTLS does CVE-2015-0282 exploit?
CVE-2015-0282 exploits the RSA PKCS #1 signature algorithm verification process.