CVE-2015-2091: Medium severity gnutls vulnerability
Published Mar 13, 2015
·Updated
The authentication hook (mgshookauthz) in mod-gnutls 0.5.10 and earlier does not validate client certificates when "GnuTLSClientVerify require" is set, which allows remote attackers to spoof clients via a crafted certificate.
Affected Software
1 affected component
Apache Mod-gnutls<=0.5.1
Event History
Mar 13, 2015
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-2091?
CVE-2015-2091 has a medium severity level due to the potential for client spoofing.
2
How do I fix CVE-2015-2091?
To fix CVE-2015-2091, upgrade mod-gnutls to version 0.5.10 or later.
3
What software is affected by CVE-2015-2091?
CVE-2015-2091 affects mod-gnutls versions 0.5.10 and earlier.
4
Can CVE-2015-2091 lead to unauthorized access?
Yes, CVE-2015-2091 can allow remote attackers to spoof clients, potentially leading to unauthorized access.
5
What is the root cause of CVE-2015-2091?
The root cause of CVE-2015-2091 is the failure of the authentication hook to validate client certificates properly.