Vulnerabilities > CVE-2009-5144 - 7PK - Security Features vulnerability in MOD Gnutls Project MOD Gnutls

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
HIGH
Availability impact
NONE
network
low complexity
mod-gnutls-project
CWE-254

Summary

mod-gnutls does not validate client certificates when "GnuTLSClientVerify require" is set in a directory context, which allows remote attackers to spoof clients via a crafted certificate.

Vulnerable Configurations

Part Description Count
Application
Mod_Gnutls_Project
1

Common Weakness Enumeration (CWE)