Vulnerabilities
Vulnerable Software
Gnu:  >> Gnutls  >> 2.10.3  Security Vulnerabilities
The DTLS implementation in GnuTLS 3.0.10 and earlier executes certain error-handling code only if there is a specific relationship between a padding length and the ciphertext size, which makes it easier for remote attackers to recover partial plaintext via a timing side-channel attack, a related issue to CVE-2011-4108.
CVSS Score
4.3
EPSS Score
0.003
Published
2012-01-06
Mutt 1.5.19, when linked against (1) OpenSSL (mutt_ssl.c) or (2) GnuTLS (mutt_ssl_gnutls.c), allows connections when only one TLS certificate in the chain is accepted instead of verifying the entire chain, which allows remote attackers to spoof trusted servers via a man-in-the-middle attack.
CVSS Score
6.8
EPSS Score
0.005
Published
2009-06-16


Contact Us

Shodan ® - All rights reserved