REDHAT-BUG-2467437
libgnutls: Fix intersecting empty constraints Permitted name constraints were wrongfully ignored when prior CAs only had excluded name constraints, resulting in a name constraint bypass. Reported by .
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2467437?
The severity of REDHAT-BUG-2467437 is critical due to the nature of the name constraint bypass vulnerability.
How do I fix REDHAT-BUG-2467437?
To fix REDHAT-BUG-2467437, update to the latest version of the GnuTLS library that addresses the intersecting empty constraints issue.
What systems are affected by REDHAT-BUG-2467437?
REDHAT-BUG-2467437 affects systems utilizing the GnuTLS library, particularly those relying on libgnutls for certificate verification.
What impact does REDHAT-BUG-2467437 have on security?
The impact of REDHAT-BUG-2467437 allows for potential name constraint bypass, which could lead to unauthorized access to secure communications.
Who reported REDHAT-BUG-2467437?
REDHAT-BUG-2467437 was reported by an individual or entity concerned with the security of the GnuTLS library.