REDHAT-BUG-2445762: Low severity GNUTLS GNUTLS vulnerability
gnutls matches a stapled ocsp response to the server certificate by scanning SingleResponse records, but then reads certstatus from record index 0 unconditionally. when a multi-record ocsp response is stapled such that record 0 is for a different certificate (good) and the matching record for the server certificate is later (revoked), a client with ocsp verification enabled can accept a revoked server certificate. this is observable as an order-dependent accept/reject outcome for the same revoked server certificate.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2445762?
The severity of REDHAT-BUG-2445762 is currently classified as moderate.
How do I fix REDHAT-BUG-2445762?
To fix REDHAT-BUG-2445762, update GnuTLS to the latest version provided by your distribution.
What is the impact of REDHAT-BUG-2445762?
The impact of REDHAT-BUG-2445762 includes potential certificate validation issues that could lead to man-in-the-middle attacks.
Is REDHAT-BUG-2445762 a remote vulnerability?
Yes, REDHAT-BUG-2445762 is considered a remote vulnerability as it can be exploited over the network.
What software is affected by REDHAT-BUG-2445762?
The vulnerable software affected by REDHAT-BUG-2445762 is GnuTLS.