Vulnerability Bulletins |
DSA-3437 gnutls26 - security update |
|
| Affected software | Debian |
|
Karthikeyan Bhargavan and Gaetan Leurent at INRIA discovered a flaw inthe TLS 1.2 protocol which could allow the MD5 hash function to be usedfor signing ServerKeyExchange and Client Authentication packets during aTLS handshake. A man-in-the-middle attacker could exploit this flaw toconduct collision attacks to impersonate a TLS server or anauthenticated TLS client. More info: https://www.debian.org/security/2016/dsa-3437 |
|






