Signature Algorithm Mismatch Vulnerability in GnuTLS by GnuTLS
CVE-2015-0282
Currently unrated
Summary
The vulnerability in GnuTLS prior to version 3.1.0 involves a failure to ensure that the RSA PKCS #1 signature algorithm corresponds with the signature algorithm specified in the certificate. This oversight enables remote attackers to execute downgrade attacks through various, unspecified vectors, potentially compromising secure communications.
References
Timeline
Vulnerability published
Vulnerability Reserved