CVE-2015-0282
24.03.2015, 17:59
GnuTLS before 3.1.0 does not verify that the RSA PKCS #1 signature algorithm matches the signature algorithm in the certificate, which allows remote attackers to conduct downgrade attacks via unspecified vectors.Enginsight
| Vendor | Product | Version |
|---|---|---|
| gnu | gnutls | 𝑥 ≤ 3.0.9 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| gnutls26 |
| ||||||||||||||||||
| gnutls28 |
|
Common Weakness Enumeration
References