Vulnerability Bulletins

DSA-3177 mod-gnutls - security update

   
Affected software Debian
 
Thomas Klute discovered that in mod-gnutls, an Apache module providingSSL and TLS encryption with GnuTLS, a bug caused the servers clientverify mode not to be considered at all, in case the directorysconfiguration was unset. Clients with invalid certificates were thenable to leverage this flaw in order to get access to that directory.

More info:

https://www.debian.org/security/2015/dsa-3177