CVE-2009-5144

mod-gnutls does not validate client certificates when "GnuTLSClientVerify require" is set in a directory context, which allows remote attackers to spoof clients via a crafted certificate.
Configurations

Configuration 1 (hide)

cpe:2.3:a:mod_gnutls_project:mod_gnutls:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2018-02-03 15:29

Updated : 2024-02-28 16:25


NVD link : CVE-2009-5144

Mitre link : CVE-2009-5144

CVE.ORG link : CVE-2009-5144


JSON object : View

Products Affected

mod_gnutls_project

  • mod_gnutls
CWE
CWE-254

7PK - Security Features