Signature Algorithm Mismatch Vulnerability in GnuTLS by GnuTLS
CVE-2015-0282

Currently unrated

Key Information:

Vendor
Gnu
Status
Vendor
CVE Published:
24 March 2015

Summary

The vulnerability in GnuTLS prior to version 3.1.0 involves a failure to ensure that the RSA PKCS #1 signature algorithm corresponds with the signature algorithm specified in the certificate. This oversight enables remote attackers to execute downgrade attacks through various, unspecified vectors, potentially compromising secure communications.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.