CVE-2008-4989 describes a critical vulnerability in GnuTLS versions prior to 2.6.1, specifically within the _gnutls_x509_verify_certificate function. This flaw allows man-in-the-middle attackers to spoof certificates for any Distinguished Name by exploiting the library's improper trust in certificate chains ending with an arbitrary trusted, self-signed certificate. Affecting various distributions like Debian, Fedora, and openSUSE, this vulnerability carries a CVSS score of 5.9 (Medium) due to its high impact on integrity and high attack complexity, despite not requiring user interaction. While no public exploit code or active exploitation has been identified, and it is not on the KEV catalog, the vulnerability has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.6.1CPE matchmatch criteria | cpe:2.3:a:gnu:gnutls:*:*:*:*:*:*:*:* | ||
8CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:8:*:*:*:*:*:*:* | ||
9CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:9:*:*:*:*:*:*:* | ||
6.06CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:6.06:*:*:*:*:*:*:* | ||
7.10CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:7.10:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.